Vulnerabilities

Google Patches High-Severity Chrome Vulnerability in Latest Update

Chrome’s latest release addresses a high-severity use-after-free vulnerability in the V8 JavaScript engine that could be exploited for remote code execution.

Chrome's latest release addresses a high-severity use-after-free vulnerability in the V8 JavaScript engine that could be exploited for remote code execution.

Google on Tuesday released Chrome 140 to the stable channel with patches for six vulnerabilities, including a four reported by external researchers.

The most severe of the bugs is CVE-2025-9864, a high-severity use-after-free issue in the V8 JavaScript engine that was reported by the Yandex Security Team.

According to Google’s advisory, no bug bounty reward will be paid for this security defect, and bug details will be kept restricted until the patches reach most users.

A type of memory corruption flaws, use-after-free vulnerabilities in V8 occur when JavaScript code can access objects after their memory has been deallocated, which can lead to heap corruption.

Attackers can potentially exploit the heap corruption via crafted HTML pages, often for remote code execution (RCE).

The remaining three security defects reported by external researchers are medium-severity inappropriate implementation bugs in Chrome’s Toolbar, Extensions, and Downloads components.

Advertisement. Scroll to continue reading.

Google says it handed out rewards of $5,000, $4,000, and $1,000 for them, respectively. The Extensions flaw was reported in November 2024.

The latest Chrome iteration is now rolling out as versions 140.0.7339.80/81 for Windows and macOS, and as version 140.0.7339.80 for Linux. The extended stable channel has been updated to Chrome 140.0.7339.81 for both Windows and macOS.

Google makes no mention of any of these vulnerabilities being exploited in the wild, but users are advised to update their browsers as soon as possible.

Related: Sangoma Patches Critical Zero-Day Exploited to Hack FreePBX Servers

Related: Password Managers Vulnerable to Data Theft via Clickjacking

Related: Flaw Allowing Website Takeover Found in WordPress Plugin With 400k Installations

Related: Windows’ Infamous ‘Blue Screen of Death’ Will Soon Turn Black

Related Content

Vulnerabilities

The browser refresh resolved critical and high-severity security defects, including a dozen use-after-free bugs.

Vulnerabilities

The vulnerability is tracked as CVE-2026-11645 and it was reported in late April by an anonymous researcher.

Vulnerabilities

Over 100 bugs are critical or high-severity, mainly use-after-free and insufficient validation of untrusted input flaws.

Vulnerabilities

The browser update resolves critical-severity security defects that could potentially lead to remote code execution.

Artificial Intelligence

More than 200 vulnerabilities patched in recent Chrome releases are marked as ‘reported by Google’.

Vulnerabilities

The refresh resolves critical-severity use-after-free and other types of bugs in various browser components.

Artificial Intelligence

Lax extension permissions and improper trust implementation allow attackers to inject prompts in the Claude Chrome extension.

Vulnerabilities

The fresh browser update resolves critical-severity integer overflow and use-after-free vulnerabilities.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version