Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Vulnerabilities

Google Patches High-Severity Chrome Vulnerability in Latest Update

Chrome’s latest release addresses a high-severity use-after-free vulnerability in the V8 JavaScript engine that could be exploited for remote code execution.

Google on Tuesday released Chrome 140 to the stable channel with patches for six vulnerabilities, including a four reported by external researchers.

The most severe of the bugs is CVE-2025-9864, a high-severity use-after-free issue in the V8 JavaScript engine that was reported by the Yandex Security Team.

According to Google’s advisory, no bug bounty reward will be paid for this security defect, and bug details will be kept restricted until the patches reach most users.

A type of memory corruption flaws, use-after-free vulnerabilities in V8 occur when JavaScript code can access objects after their memory has been deallocated, which can lead to heap corruption.

Attackers can potentially exploit the heap corruption via crafted HTML pages, often for remote code execution (RCE).

The remaining three security defects reported by external researchers are medium-severity inappropriate implementation bugs in Chrome’s Toolbar, Extensions, and Downloads components.

Advertisement. Scroll to continue reading.

Google says it handed out rewards of $5,000, $4,000, and $1,000 for them, respectively. The Extensions flaw was reported in November 2024.

The latest Chrome iteration is now rolling out as versions 140.0.7339.80/81 for Windows and macOS, and as version 140.0.7339.80 for Linux. The extended stable channel has been updated to Chrome 140.0.7339.81 for both Windows and macOS.

Google makes no mention of any of these vulnerabilities being exploited in the wild, but users are advised to update their browsers as soon as possible.

Related: Sangoma Patches Critical Zero-Day Exploited to Hack FreePBX Servers

Related: Password Managers Vulnerable to Data Theft via Clickjacking

Related: Flaw Allowing Website Takeover Found in WordPress Plugin With 400k Installations

Related: Windows’ Infamous ‘Blue Screen of Death’ Will Soon Turn Black

Written By

Ionut Arghire is an international correspondent for SecurityWeek.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Today’s attackers are no longer breaking in — they’re logging in. Join this live webinar as we break down the modern identity attack chain and examine how recent breaches exploited weaknesses in authentication, identity verification, and access management processes.

Register

AI has accelerated both sides of the fight. Adversaries are weaponizing vulnerabilities faster, while defenders are racing to ship detections and configurations. Join this live webinar as we explore how to prove your controls actually hold against new threats, map your security maturity, and unite breach simulation with automated pentesting into a single, coordinated program.

Register

People on the Move

Stephen Garcia has been named Chief Information Security Officer at BreachRx.

Kasper Lindgaard has been appointed Vice President of Security Strategy at CoreView.

Chaim Mazal has been named Chief Information Security Officer at GitLab.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.