Advisory

Google releases Chrome security update patching multiple flaws, two high severity

Take action: An easy update of your Chrome and Chromium based browsers (Opera, Edge, Brave, Vivaldi...). This one may become critical, so don't delay. Update your browsers now - all your tabs reopen so it's super easy.


Learn More

Google has released Chrome 137.0.7151.55 for Linux and Chrome 137.0.7151.55/56 for Windows and Mac, addressing multiple vulnerabilities. These vulnerabilities, if left unpatched, could allow attackers to execute arbitrary code, corrupt memory, or crash the browser.

Vulnerabilities summary

  • CVE-2025-5063 (CVSS score 8.8) - Use after free in Compositing
  • CVE-2025-5280 (CVSS score 8.8) - Out of bounds write in V8
  • CVE-2025-5065 (CVSS score 6.5) - Inappropriate implementation in FileSystemAccess API
  • CVE-2025-5066 (CVSS score 6.5) - Inappropriate implementation in Messages
  • CVE-2025-5064 (CVSS score 5.4) - Inappropriate implementation in Background Fetch API
  • CVE-2025-5281 (CVSS score 5.4) - Inappropriate implementation in BFCache
  • CVE-2025-5283 (CVSS score 5.4) - Use after free in libvpx
  • CVE-2025-5067 (CVSS score 5.4) - Inappropriate implementation in Tab Strip 

The use-after-free vulnerabilities in Compositing and libvpx components are  concerning as they represent memory management flaws that can be exploited to achieve code execution. The out-of-bounds write vulnerability in the V8 JavaScript engine could potentially allow attackers to corrupt memory through maliciously crafted web content. 

Google maintains its policy of restricting access to detailed bug information until a majority of users have been updated with the fixes. This restriction also applies to vulnerabilities in third-party libraries that other projects depend on but haven't yet addressed.

Users are encouraged to ensure their Chrome browsers are updated to the latest version across all platforms to maintain security.

Google releases Chrome security update patching multiple flaws, two high severity