Google releases Chrome security update patching high-severity JavaScript engine flaws
Take action: This one is not urgent, but it's the smart thing to do. Update your Chrome and Chromium based browsers (Opera, Brave, Vivaldi, Edge...). These vulnerabilities will eventually be exploited so don't ignore patching. And it's super easy, all your tabs reopen.
Learn More
Google has released an security update for its Chrome browser, patching multiple high severity flaws.
Vulnerabilities summary
- CVE-2025-8010 (CVSS score 8.8) - type confusion vulnerability in V8 JavaScript engine. This flaw allows remote attackers to potentially exploit heap corruption through crafted HTML pages, enablingarbitrary code execution.
- CVE-2025-8011 (CVSS score 8.8) - type confusion vulnerability in V8 JavaScript engine. Similar to CVE-2025-8010, this vulnerability enables remote attackers to exploit browser weaknesses via specially crafted web content.
- Additional internal security fixes discovered through Google's comprehensive internal security auditing processes, using advanced detection tools and methodologies to identify potential vulnerabilities before they reach production environments.
The stable channel has been updated to version 138.0.7204.168/.169 for Windows and Mac, and 138.0.7204.168 for Linux, with the rollout expected to reach all users over the coming days and weeks.
The company maintains a policy of restricting access to detailed vulnerability information and technical specifics until the majority of users have successfully updated their browsers with the necessary security fixes.