Google fixes high-risk Chrome vulnerabilities with June replace
Google has launched a safety replace for its Chrome browser. Two vulnerabilities have been mounted within the new Chrome variations 137.0.7151.103/104 for Home windows and macOS and 137.0.7151.103 for Linux. Based on Google, not one of the vulnerabilities are being exploited for assaults within the wild. The producers of different Chromium-based browsers will comply with swimsuit within the coming days.
Within the Chrome Releases weblog publish, Prudhvikumar Bommana lists the 2 vulnerabilities that had been found by exterior safety researchers and reported to Google. Google classifies each vulnerabilities as excessive danger. CVE-2025-5958 is a use-after-free vulnerability within the Media element. If profitable, an attacker might inject and execute arbitrary code.
The second vulnerability, CVE-2025-5959, was demonstrated on the TyphoonPWN hacker competitors on the finish of Could, which has been going down since 2018 as a part of the TyphoonCon safety convention in Seoul. The vulnerability is as soon as once more a sort mix-up within the V8 JavaScript engine, which can be used to execute injected code.
Google has additionally launched Chrome for Android 137.0.7151.89, which fixes the identical vulnerabilities within the Android model of the browser as within the desktop variations.
Chrome often updates itself robotically when a brand new model is obtainable. However should you aren’t as much as the newest model but, you’ll be able to manually provoke an replace examine utilizing the three-dot menu and navigating to Assist > About Google Chrome. Google plans to launch Chrome model 138 on the finish of June.
Different Chromium-based browsers
The producers of different Chromium-based browsers must be following swimsuit with their very own updates quickly.
Courageous and Microsoft Edge have already switched to Chromium 137 and are at the moment on the safety stage previous to this Chrome replace. Vivaldi as soon as once more depends on the Prolonged Steady Channel of the earlier model and is due to this fact on the similar safety stage as Courageous and Edge.
However Opera’s browser nonetheless makes use of the outdated Chromium 134, for which Google not offers safety updates.
This text initially appeared on our sister publication PC-WELT and was translated and localized from German.