Google has officially announced the release of Chrome 142 to the stable channel, delivering critical security updates for Windows, Mac, and Linux users. The rollout begins immediately and will continue over the coming days or weeks, ensuring broad protection against newly discovered threats.

This release addresses 20 vulnerabilities, many of which could allow attackers to execute malicious code remotely, compromising user data and system integrity. The update underscores Google's commitment to responding promptly to evolving browser-based attacks.
Chrome versions 142.0.7444.59 for Linux, 142.0.7444.59/60 for Windows , and 142.0.7444.60 for Mac incorporate a number of fixes and performance improvements.
See also: Windows Accessibility bug allows persistence and lateral movement
Detailed changelogs are available via the Chromium source repository, highlighting improvements to performance, stability, and the user interface. While full details on the new features will appear in upcoming posts on the Chrome and Chromium blogs, the immediate priority is to strengthen defenses against exploit attempts.
Security experts recommend that users enable automatic updates to immediately mitigate risks, as out-of-date browsers remain prime targets for cybercriminals.

Chrome 142: Fix 20 vulnerabilities
As previously mentioned, the update addresses a wide range of vulnerabilities. Details of the bugs will initially remain confidential until global availabilityto avoid facilitating active exploits. Several fixes come from external researcherswho earned rewards under Google's Vulnerability Bounty Program, while others come from internal audits and fuzzing tools like AddressSanitizer and libFuzzer.
See also: Google Messages – Wear OS: Vulnerability allows apps to send SMS
High-severity issues dominate, particularly in the V8 JavaScript engine, where type confusion, race conditions, and improper implementations could lead to arbitrary code execution.
Media management and extensions also receive special attention, closing loopholes that could allow unauthorized access or policy bypasses . Lower-severity fixes address UI and storage race issues, preventing small but persistent risks.
See also: CISA warns of vulnerabilities in DELMIA Apriso platform

In the table below, you can see the vulnerabilities fixed with Chrome version 142:
| CVE ID | Severity | Description | Reporter | Bounty | Report Date |
|---|---|---|---|---|---|
| CVE-2025-12428 | High | Type Confusion in V8 | Man Yue Mo (GitHub Security Lab) | $50,000 | 2025-09-26 |
| CVE-2025-12429 | High | Inappropriate implementation in V8 | Aorui Zhang | $50,000 | 2025-10-10 |
| CVE-2025-12430 | High | Object lifecycle issue in Media | round.about | $10,000 | 2025-09-04 |
| CVE-2025-12431 | High | Inappropriate implementation in Extensions | Alessandro Ortiz | $4,000 | 2025-08-06 |
| CVE-2025-12432 | High | Race in V8 | Google Big Sleep | N/A | 2025-08-18 |
| CVE-2025-12433 | High | Inappropriate implementation in V8 | Google Big Sleep | N/A | 2025-10-07 |
| CVE-2025-12036 | High | Inappropriate implementation in V8 | Google Big Sleep | N/A | 2025-10-15 |
| CVE-2025-12434 | Medium | Race in Storage | Lijo AT | $3,000 | 2024-04-27 |
| CVE-2025-12435 | Medium | Incorrect security UI in Omnibox | Hafizh | $3,000 | 2025-09-21 |
| CVE-2025-12436 | Medium | Policy bypass in Extensions | Luan Herrera (@lbherrera_) | $2,000 | 2021-02-08 |
Google thanks the contributors who helped eliminate these bugs before they were exploited by hackers. Internal efforts, including fuzzing and sanitizer tools, contributed to numerous fixes, preventing a wide range of potential exploits. As browser usage increases alongside phishing and malware campaigns, this release reinforces Chrome’s position as the secure default for billions of users. Users should verify updates via chrome://settings/help to stay protected.
