HomeinetChrome security update fixes multiple critical flaws

Chrome security update fixes multiple critical flaws

Google has released a critical security update for its Chrome browser, addressing multiple critical flaws that could allow arbitrary code execution and sandbox escapes.

See also: Chrome: Malicious extensions are “transforming” into password managers

Chrome critical flaws

The Stable Channel update 134.0.6998.88/.89 for Windows and Mac and 134.0.6998.88 for Linux, released on March 10, 2025, includes fixes for five security flaws, three of which are rated as high risk.

At the same time, the Extended Stable Channel , which is primarily used by businesses for staged testing, has been updated to 134.0.6998.89 for Windows and Mac, with its staged release planned in the coming weeks.

This update follows a pattern of increased scrutiny of V8 JavaScript and GPU components, which remain prime targets for exploitation.

The most critical fixes target CVE-2025-1920 and CVE-2025-2135, two types of confusion vulnerabilities in the V8 JavaScript engine.

CVE-2025-1920, reported by Excello sro, earned a $7,000 bounty, while CVE-2025-2135, identified by Zhenghang Xiao (@Kipreyyy), highlights ongoing risks in the V8 architecture.

See also: Chrome 134 and Firefox 136 fix critical vulnerabilities

A third critical flaw in Chrome, CVE-TBD , involves an out-of-bounds write to Chrome's GPU component

Chrome security update fixes multiple critical flaws

The update also addresses CVE-2025-2136, a non-use flaw in the Inspector, and CVE-2025-2137, an out-of-bounds write flaw in V8.

While Google has not confirmed that these critical flaws in Chrome are actively being exploited, their severity requires immediate action. Attackers could exploit these issues through drive-by attacks, where simply visiting a malicious website triggers the exploit.

Although Chrome updates automatically, users must manually restart the browser to activate the latest patches—an often overlooked step.

See also: Google Chrome: Enhanced protection with AI is coming to all users!

High severity vulnerabilities refer to security flaws in software, systems, or applications that can have a significant impact on the confidentiality, integrity, or availability of data or services. These vulnerabilities are often the most critical to address because they can be exploited by attackers to gain unauthorized access, cause operational disruption, or steal sensitive information. They typically have a high risk of exploitation and can lead to serious consequences if not mitigated.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Source: cybersecuritynews

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS