HomeUpdatesChrome update fixes critical RCE vulnerability

Chrome update fixes critical RCE vulnerability

Google has issued an urgent security update for its Chrome browser on Windows, Mac, and Linux, addressing a critical vulnerability that could allow attackers to execute arbitrary code remotely .

Chrome Update

Users are urged to update their browsers immediately to protect themselves from potential threats. The update is available now and will be available to all users in the coming days and weeks. This fix follows the initial release of Chrome 140, which also addressed several other security issues.

Chrome: Critical Use-After-Free Vulnerability

In fact, the new update fixes two major security flaws, the most serious of which is CVE-2025-10200. This vulnerability has been rated as critical and is described as a “Use-after-free” bug in the Serviceworker component.

A use-after-free error can lead to crashes, data corruption, or, in the worst case, arbitrary code execution. An attacker could exploit this vulnerability by creating a malicious web page. When a user visits the page, the attacker could execute malicious code on their system.

See also: Windows BitLocker vulnerability allows elevation of privilege attack

Security researcher Looben Yang reported this critical bug on August 22, 2025. Recognizing the severity of the vulnerability, Google awarded a bug bounty of $43,000.

Bug in Mojo Implementation

The second vulnerability fixed in this release is CVE-2025-10201, a high-severity bug identified as “Inappropriate implementation in Mojo.” Mojo is a collection of runtime libraries used for inter-process communication in Chromium, the open-source project that powers Chrome.

Chrome update fixes critical RCE vulnerability

Bugs in this component can be particularly dangerous as they can compromise the browser's sandbox, a key security feature that isolates processes to prevent potential exploits from affecting the underlying system. This vulnerability was reported by Sahan Fernando and an anonymous researcher on August 18, 2025. The researchers received a bug bounty of $30,000 for their findings.

Google is rolling out the update gradually, but users can check and apply the update manually by going to Settings > About Google Chrome. The browser will automatically scan for the latest version and prompt the user to restart it to complete the update process.

As is standard practice, Google has restricted access to detailed information about the bugs to prevent attackers from developing exploits before the majority of users install the update. This underscores the importance of applying security updates as soon as they become available.

See also: Adobe Commerce bug allows account takeover

Chrome security

Chrome's latest critical update isn't just another security patch — it's a reminder of how vulnerable our daily web browsing is. Chrome, with billions of users worldwide, is a prime target for cyberattacks, as a single vulnerability can open the door to a vast number of devices. The fact that the CVE-2025-10200 bug could allow arbitrary code execution shows how thin the line is between a simple crash and a serious data breach.

Chrome update fixes critical RCE vulnerability

Google now follows a bug bounty policy for security researchers, investing tens of thousands of dollars to “buy” knowledge before cybercriminals exploit. This in itself shows that browser security is not a luxury but a matter of digital hygiene.

See also: Microsoft Patch Tuesday September 2025: 81 Vulnerabilities Fixed

For users, the lesson is clear: updates are not annoying pop-ups that slow down our work, but critical shields of protection. And as attacks become more sophisticated, the speed with which we apply these fixes can mean the difference between protection and breach.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS