Vulnerability News

Chrome Buffer Overflow Vulnerabilities Allow Arbitrary Code Execution & Gain System Access

Google has urgently patched two high-severity heap buffer overflow vulnerabilities in its Chrome browser, CVE-2025-0999, and CVE-2025-1426, that could allow attackers to execute arbitrary code and seize control of affected systems.

The vulnerabilities, fixed in Chrome 133.0.6943.126/.127 for Windows/Mac and 133.0.6943.126 for Linux, target the V8 JavaScript engine and GPU components, respectively.

Multiple High-Severity Vulnerabilities

The V8 engine vulnerability (CVE-2025-0999) arises from improper memory management when processing JavaScript objects, enabling heap corruption through crafted HTML pages.

Separately, the GPU flaw (CVE-2025-1426) exploits Chrome’s graphics processing unit integration, allowing attackers to overflow buffer limits during rendering operations.

Both vulnerabilities grant remote code execution (RCE) capabilities, potentially enabling full system compromise, data theft, or lateral movement within networks.

Heap buffer overflow vulnerability enables attackers to overwrite dynamically allocated memory regions and execute arbitrary code. This vulnerability arises when programs write data beyond the bounds of memory blocks allocated on the heap a dynamically managed memory area used for runtime data storage.

Another vulnerability is CVE-2025-1006, a medium-severity use-after-free (UAF) vulnerability in Google Chrome’s Network component. Attackers could exploit it by crafting malicious web content to trigger arbitrary code execution, potentially compromising user systems or exfiltrating sensitive data

External researchers have discovered several vulnerabilities. Seunghyun Lee (@0x10n) received an $11,000 bounty for CVE-2025-0999. The team “un3xploitable && GF” is awaiting a reward for CVE-2025-1426. Additionally, researchers from Palo Alto Networks (Tal Keren, Sam Agranat, Eran Rom, Edouard Bochin, and Adam Hatsir) were awarded $4,000 for CVE-2022-4135.

Google has withheld full technical details until most users update, a standard practice to prevent exploit weaponization.

While no active exploitation has been confirmed, the similarities to prior Chrome zero-days, such as CVE-2022-4135, a GPU heap overflow exploited in 2022, heighten concerns. Chrome’s dominance (65% global browser share) makes it a prime target for attackers seeking maximum impact.

Users must immediately update via Chrome > Help > About Google Chrome, restarting the browser to apply patches. Enterprise administrators should prioritize deploying the update across networks, as delayed patching leaves systems exposed to drive-by download attacks or phishing campaigns delivering exploit code.

As attackers increasingly chain multiple vulnerabilities for systemic breaches, users and organizations cannot afford complacency. With Chrome updates automated by default, vigilance now centers on ensuring update mechanisms function correctly across all devices.

Update Steps for Chrome:

  1. Open Chrome and click the three-dot menu (top-right).
  2. Navigate to Help > About Google Chrome.
  3. Allow the browser to check for updates.
  4. Click Relaunch if an update is available.

Google continues to credit external researchers through its Vulnerability Rewards Program, having disbursed over $12 million since 2010.

Investigate Real-World Malicious Links & Phishing Attacks With Threat Intelligence Lookup - Try for Free

Guru Baran

Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.

Recent Posts

Top 10 Best SaaS Security Posture Management (SSPM) Tools in 2026

Your SaaS estate M365, Salesforce, Workday, Slack, hundreds of others is a sprawl of misconfigurations,…

1 minute ago

Top 10 Best Data Security Posture Management (DSPM) Tools in 2026

DSPM finds sensitive data you didn’t know you had, classifies it, maps who can reach…

7 minutes ago

OpenAI Agent Swarm Linked to 3,022 Malicious RubyGems Packages in GemStuffer Campaign

Open-source packages are meant to save developers time. In the GemStuffer campaign, that trust became…

18 minutes ago

Google Chrome 153 Update Fixes 42 Security Flaws, Including 3 Critical Ones

Google has released an important Chrome 153 security update that fixes 42 vulnerabilities across the…

5 hours ago

CISA and NIST Release Technical Checklist for Safeguarding Identity Tokens From Theft and Misuse

The Cybersecurity and Infrastructure Security Agency (CISA) and the National Institute of Standards and Technology…

15 hours ago

CISA Shares 17 Techniques Used by Hackers to Compromise Active Directory Environments

CISA and five international cybersecurity agencies have released detailed guidance describing 17 common techniques hackers…

16 hours ago