Advisory

Chrome 140 security update patches six vulnerabilities, one high-severity

Take action: Finally an update without a critical actively exploited vulnerability. Still wise to update your Chrome, Edge, Opera, Brave, Vivaldi... Because hackers will find a way to exploit these flaws. Don't wait, updating is trivial and all your tabs reopen.


Learn More

Google has released Chrome 140 patching six security vulnerabilities, one classified as high severity but with a critical CVSS score. 

Vulnerabilities summary:

  • CVE-2025-9864 (CVSS score 9.8, Google score High severity) - Use after free in V8 JavaScript engine
  • CVE-2025-9865 (CVSS score 8.8, Google score Medium severity) - Inappropriate implementation in Toolbar
  • CVE-2025-9866 (CVSS score 8.8, Google score Medium severity) - Inappropriate implementation in Extensions
  • CVE-2025-9867 (CVSS score 8.8, Google score Medium severity) - Inappropriate implementation in Downloads

Chrome 140 is available as 140.0.7339.80 for Linux systems and 140.0.7339.80/81 for Windows and Mac platforms. The Extended Stable channel has also been updated to version 140.0.7339.81 for Windows and Mac users who prefer the more conservative update schedule. Users can verify their current Chrome version by navigating to Settings > About Chrome, where the browser will automatically check for and install available updates.

Google restricts access to detailed vulnerability information until a majority of users have updated their browsers with the fixes.

Chrome 140 security update patches six vulnerabilities, one high-severity