Cyber Security News

Multiple Chrome Vulnerabilities Let Attackers Execute Arbitrary Code

Google has rolled out a critical security update for Chrome 135 across all desktop platforms. The update addresses fourteen vulnerabilities, including high-severity flaws that could enable remote code execution.

The stable channel update (135.0.7049.52 for Linux, 135.0.7049.41/42 for Windows/macOS) comes with urgent patches for multiple memory corruption and implementation flaws actively exploited in the wild.

High-Severity Vulnerability

The most severe vulnerability (CVE-2025-3066) involves a use-after-free flaw in navigation processes that could let attackers execute arbitrary code via crafted web pages.

Reported by Sven Dysthe through Chrome’s Vulnerability Reward Program, this memory corruption flaw carries a “High” severity rating.

Medium-Risk Vulnerabilities

Five medium-severity fixes address implementation flaws across key components:

  • Custom Tabs vulnerability (CVE-2025-3067) allowing privilege escalation ($10,000 bounty).
  • Intents handler bypass (CVE-2025-3068) enabling unauthorized actions ($2,000 bounty).
  • Extension system flaws (CVE-2025-3069/3070) permitting malicious payload injection.

Notably, one extension vulnerability report dates back to 2017, revealing long-standing architectural issues in Chrome’s permission model.

Low-Severity Vulnerabilities

The update resolves four lower-risk implementation issues:

  • Navigation handling (CVE-2025-3071)
  • Custom Tabs validation (CVE-2025-3072)
  • Autofill protections (CVE-2025-3073)
  • Download protections (CVE-2025-3074)

External researchers claimed $17,000 in bounties for identifying vulnerabilities, with TU Wien researcher Philipp Beer receiving the highest individual payout. The patch also includes fixes from Google’s internal security teams using advanced hardening measures:

Update Recommendations

Chrome users should immediately:

  1. Navigate to chrome://settings/help
  2. Allow automatic update installation
  3. Restart the browser

Enterprise administrators can force updates through group policies (version 135.0.7049.52+). Google has restricted detailed technical disclosures until most users update, following standard coordinated vulnerability disclosure practices.

This update highlights Chrome’s ongoing security challenges despite massive investments in sandboxing and process isolation. The inclusion of vulnerabilities reported as early as 2017 suggests some architectural limitations persist in the browser’s 16-year-old codebase.

Investigate Real-World Malicious Links & Phishing Attacks With Threat Intelligence Lookup - Try 50 Request for Free

Guru Baran

Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.

Recent Posts

Microsoft Releases Emergency Windows 11 Update Following Patch Tuesday Bugs

Microsoft has pushed out an emergency, out-of-band Windows 11 update after its September Patch Tuesday…

11 minutes ago

Top 10 Best Cloud Detection & Response (CDR) Solutions in 2026

CDR is the runtime, real-time half of cloud security: while CSPM tells you what’s misconfigured,…

16 minutes ago

Top 10 Best SaaS Security Posture Management (SSPM) Tools in 2026

Your SaaS estate M365, Salesforce, Workday, Slack, hundreds of others is a sprawl of misconfigurations,…

21 minutes ago

Top 10 Best Data Security Posture Management (DSPM) Tools in 2026

DSPM finds sensitive data you didn’t know you had, classifies it, maps who can reach…

27 minutes ago

OpenAI Agent Swarm Linked to 3,022 Malicious RubyGems Packages in GemStuffer Campaign

Open-source packages are meant to save developers time. In the GemStuffer campaign, that trust became…

38 minutes ago

Google Chrome 153 Update Fixes 42 Security Flaws, Including 3 Critical Ones

Google has released an important Chrome 153 security update that fixes 42 vulnerabilities across the…

5 hours ago