Memory Safety
The latest Memory Safety coverage — news, analysis, and updates from the WindowsNews.AI desk.
Microsoft Ships Rust Kernel Code, But Certification Keeps Driver Ecosystem in Limbo
A Rust-compiled kernel component has already shipped inside Windows 11 24H2, yet device-driver teams looking to adopt the language face a certification maze that keeps Rust out of production driver...
Google Chrome 139.0.7258.127 Plugs Aura Use-After-Free (CVE-2025-8882) and Other High-Severity Bugs
Google has deployed a critical stable-channel update for Chrome, version 139.0.7258.127, closing a use-after-free vulnerability in the Aura UI component tracked as CVE-2025-8882. The patch also...
Chrome 139 Fixes High-Severity libaom AV1 Heap Overflow; Edge Patch to Follow
Google has rolled out a stable-channel update for Chrome that patches CVE-2025-8879, a high-severity heap buffer overflow in the libaom AV1 codec library. The fix landed on August 12, 2025, in Chrome...
CVE-2025-50155: Critical Windows Push Notifications EoP Flaw Exposes Systems to Full Takeover
A serious elevation-of-privilege vulnerability in Windows Push Notifications has been cataloged as CVE-2025-50155 by Microsoft, giving authenticated local attackers a clear path to SYSTEM-level...
Microsoft Issues Advisory for Critical Excel RCE Flaw CVE-2025-53739, Urges Immediate Patching
A newly discovered vulnerability in Microsoft Excel, tracked as CVE-2025-53739, could allow attackers to execute arbitrary code on victims' machines simply by convincing them to open a specially...
Microsoft Office Buffer Over-Read Bugs Strike Word and Excel: What Enterprises Must Patch Now
Microsoft has rolled out crucial patches for two high-severity buffer over-read vulnerabilities in Microsoft Word and Excel, both enabling local attackers to extract sensitive memory contents. The...
Windows Notification Use‑After‑Free Vulnerability (CVE‑2025‑49725) Grants Attackers SYSTEM Privileges
Microsoft has patched a critical use‑after‑free vulnerability in the Windows Notification subsystem that could allow an authenticated local attacker to escalate privileges to SYSTEM. Tracked as...
Microsoft Issues Urgent Fix for CVE-2025-53724: Windows Push Notifications Type Confusion Bug Enables SYSTEM Access
Microsoft’s latest security advisory warns of a serious elevation-of-privilege vulnerability in the Windows Push Notifications Apps component, tracked as CVE-2025-53724. The flaw, rooted in a type...
Patch Now: CVE-2025-53140 Kernel Transaction Manager Use-After-Free Enables Local Privilege Escalation on Windows
Microsoft has released a security update for CVE-2025-53140, a use-after-free vulnerability in the Windows Kernel Transaction Manager (KTM) that allows an authorized local attacker to elevate...
137 Fixes and a Win32K Type-Confusion Bug: Microsoft’s Mammoth July Patch Tuesday
Microsoft’s July 2025 security update is a behemoth, shipping patches for 137 vulnerabilities, including a zero-day in SQL Server and a heap of critical remote code execution flaws. But buried in...
Windows Security Future Tied to Hardware: NPUs, Rust, and Post-Quantum Crypto Require New Devices
Microsoft is drawing a hard line between next-generation Windows security and the silicon that runs it. A sweeping vision penned by David Weston, the company’s Vice President of Enterprise and OS...
Chrome 138.0.7204.183 Fixes Critical CVE-2025-8292 Use-After-Free Flaw in Media Stream
Google has rolled out Chrome version 138.0.7204.183 to address a high-severity security flaw that could let attackers hijack systems through nothing more than a malicious webpage. Tracked as...