Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Vulnerabilities

Chrome 143 Patches High-Severity Vulnerabilities

Chrome 143 stable was released with patches for 13 vulnerabilities, including a high-severity flaw in the V8 JavaScript engine.

Chrome security

Google on Tuesday promoted Chrome 143 to the stable channel with patches for 13 vulnerabilities reported by external researchers.

The fresh round of Chrome patches resolves four high-severity flaws, including a type confusion issue in the V8 JavaScript and WebAssembly engine, tracked as CVE-2025-13630.

The remaining high-severity defects include inappropriate implementation bugs in Google Updater (CVE-2025-13631) and DevTools (CVE-2025-13632), and a use-after-free flaw in Digital Credentials (CVE-2025-13633).

Google says that it handed out $11,000 for the V8 vulnerability, and $3,000 for the Google Updater bug.

The Chrome 143 patches address three medium-severity security holes: an inappropriate implementation flaw in Downloads, a bad cast bug in Loader, and a race condition in V8.

The remaining six vulnerabilities addressed with the release of Chrome 143 are low-severity flaws.

Advertisement. Scroll to continue reading.

They include five inappropriate implementation defects in Downloads, Split View, WebRTC, and Passwords, and a use-after-free issue in Media Stream.

Google says it paid $18,000 in bug bounty rewards for four of the vulnerabilities, but has yet to disclose the amounts for six more issues.

The internet giant makes no mention of any of these security defects being exploited in the wild.

The latest Chrome iteration is now rolling out as version 143.0.7499.40 for Linux and versions 143.0.7499.40/41 for Windows and macOS.

On Tuesday, the Chrome patches were also rolled out for Android, in Chrome version 143.0.7499.52, and Chrome for iOS was updated to version 143.0.7499.92.

Additionally, Google announced that the browser’s Extended Stable channel has been updated to version 142.0.7499.226 for Windows and macOS.

Users are advised to apply the new Chrome patches as soon as possible, as Chrome vulnerabilities are often popular targets for threat actors.

Related: Chrome, Edge Extensions Caught Tracking Users, Creating Backdoors

Related: Android Zero-Days Patched in December 2025 Security Update

Related: Fluent Bit Vulnerabilities Expose Cloud Services to Takeover

Related: SonicWall Patches High-Severity Flaws in Firewalls, Email Security Appliance

Written By

Ionut Arghire is an international correspondent for SecurityWeek.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Delve into big-picture strategies to reduce attack surfaces, improve patch management, conduct post-incident forensics, and tools and tricks needed in a modern organization.

Register

Organizations are investing heavily in third-party risk management, but breaches, delays, and blind spots continue to persist. Join this live webinar as we examine the gap between how organizations think their third-party risk programs are performing and what’s actually happening in practice.

Register

People on the Move

Rapid7 announced that Wael Mohamed will assume the role of Chief Executive Officer, replacing current Chief Executive Officer Corey Thomas, who will become Executive Chairman of the Board.

Anurag Jain has been appointed Senior Vice President of Engineering at CodeHunter.

CTERA has appointed Tal Sarfaty as Senior Vice President of Cybersecurity.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.