HomeSecurityChrome vulnerabilities allow malicious code execution

Chrome vulnerabilities allow malicious code execution

Google has released an urgent security update for Chrome, after discovering several high-severity vulnerabilities that could allow attackers to remotely execute malicious code on users' systems

See also: Chrome: Over 100 malicious extensions detected

Chrome vulnerabilities

The most critical vulnerability, a “ Use after free ” flaw in the browser’s Compositing system , poses serious risks to users who have not yet updated Chrome. Security experts warn that these vulnerabilities can be exploited to gain control of affected systems, which could lead to data theft , malware installation, or other breaches.

Users are strongly advised to immediately update Chrome to version 137.0.7151.40/.41 for Windows and Mac. On Wednesday, May 21, 2025, Google released an early stable update for Chrome, addressing eight security vulnerabilities.

The update was initially distributed to a small percentage of users as part of Google's gradual rollout strategy. However, due to the severity of the vulnerabilities, security experts recommend that all users update their browser immediately.

See also: Google updates Family Link with better parental controls

The most critical issue, codenamed CVE-2025-5063, concerns a “Use after free” vulnerability in the Compositing system, which is responsible for rendering visual elements on web pages.

Chrome vulnerabilities allow malicious code execution

Google's security team has rated this issue as "high severity" due to its potential for serious exploitation . This vulnerability could potentially allow attackers to execute malicious code remotely by tricking users into visiting specially crafted websites.

“Use-after-free” vulnerabilities are particularly dangerous, as they involve exploiting memory areas after they have already been freed, which can allow the execution of arbitrary code by the attacker.

Google's decision to move forward with an early stable release underscores the criticality of this security update, as such actions are typically only taken when there are serious threats that may already be actively exploited.

See also: New Chrome vulnerability allows data leakage

Security experts recommend enabling automatic updates for browsers and software in general to ensure timely protection against new vulnerabilities that are discovered. In addition, users should be especially careful when visiting unknown websites and avoid clicking on suspicious links or downloading files from untrusted sources.

Source: cybersecuritynews

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS