Advisory

Google releases new Chrome version, patches two high severity flaws

Take action: Another easy update of your Chrome and Chromium based browsers (Opera, Edge, Brave). This one may become critical, so don't delay. Update your browsers now - all your tabs reopen so don't delay.


Learn More

Google has released security updates for Chrome version 133 across multiple platforms, addressing several significant vulnerabilities. The updates include Chrome 133.0.6943.121 for Android and 133.0.6943.126/.127 for Windows, Mac, and Linux desktop versions.

The desktop update addresses three security vulnerabilities:

  • CVE-2025-1006 (CVSS score 9.8) - Google marks it as Medium- Use after free in Network
  • CVE-2025-0999 (CVSS score 8.8) - Heap buffer overflow in V8
  • CVE-2025-1426 (CVSS score 8.8) - Heap buffer overflow in GPU

For Android users, Chrome version 133.0.6943.121 will be available through Google Play over the next few days. This Android release includes the same security fixes as the desktop version unless specifically noted otherwise.

Additionally, Google has updated the Extended Stable channel to version 132.0.6834.209 for Windows and Mac users. This update will be rolled out gradually over the coming days and weeks.

Google maintains its policy of restricting access to detailed bug information until a majority of users have been updated with the fixes. This restriction also applies to vulnerabilities in third-party libraries that other projects depend on but haven't yet addressed.

Users are encouraged to ensure their Chrome browsers are updated to the latest version across all platforms to maintain security.

Google releases new Chrome version, patches two high severity flaws