Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Chrome 142 Update Patches High-Severity Flaws

Chrome 142 Update Patches High-Severity Flaws

Posted on November 7, 2025November 7, 2025 By CWS

Shortly after selling Chrome 142 to the steady channel, Google pushed out an replace to handle 5 vulnerabilities within the browser, together with three high-severity flaws.

The primary high-risk difficulty is CVE-2025-12725 (CVSS rating of 8.8), described as an out-of-bounds write bug in Chrome’s WebGPU graphics API, which delivers high-performance visuals by permitting web sites to work together with the system’s GPU.

Out-of-bounds defects are rooted in inadequate bounds checking, which permits attackers to write down knowledge outdoors of the meant reminiscence house, probably resulting in crashes or arbitrary code execution.

Based on SOCRadar, the rising use of browser-based AI and graphics workloads will increase the danger of the vulnerability’s exploitation.

The remaining two high-severity bugs resolved with the contemporary Chrome replace are inappropriate implementations within the Views framework and the V8 JavaScript engine, tracked as CVE-2025-12726 and CVE-2025-12727 (CVSS rating of 8.8).

The Views flaw exists as a result of UI object references are dealt with in an unsafe method, which might enable attackers to set off reminiscence corruption through crafted webpages or extensions. Profitable exploitation of the defect might additionally result in unintended entry to interface elements.

Vulnerabilities in Chrome’s V8 JavaScript and WebAssembly engine are standard targets for menace actors. Sort confusion and reminiscence corruption points in V8 are sometimes exploited for distant code execution.

The remaining two safety defects resolved with this Chrome 142 replace are medium-severity inappropriate implementations in Omnibox, tracked as CVE-2025-12728 and CVE-2025-12729.Commercial. Scroll to proceed studying.

Google makes no point out of any of those vulnerabilities being exploited within the wild. The most recent Chrome iteration is now rolling out as model 142.0.7444.134 for Linux, model 142.0.7444.135 for Mac, and variations 142.0.7444.134/.135 for Home windows.

“Browsers have quietly grow to be the one largest assault floor in practically each group. Most customers preserve dozens of tabs open all through the day, a lot of which stay lively within the background. Every of these pages can embrace scripts, advertisements, and dynamic parts that change or redirect with out discover, successfully making the browser a dwell goal surroundings,” Action1 CTO Gene Moody stated.

“Due to this, browser vulnerabilities are a steady threat as a result of exploits typically emerge and unfold quicker than conventional patch cycles can reply, which is why browser updates now launch extra regularly than virtually some other software program. In lots of instances, vital fixes arrive a number of instances every week,” Moody added.

Associated: Google Pays $100,000 in Rewards for Two Chrome Vulnerabilities

Associated: Chrome to Flip HTTPS on by Default for Public Websites

Associated: Chrome Zero-Day Exploitation Linked to Hacking Staff Spy ware

Associated: Chrome 141 and Firefox 143 Patches Repair Excessive-Severity Vulnerabilities

Security Week News Tags:Chrome, Flaws, HighSeverity, Patches, Update

Post navigation

Previous Post: Enterprise Credentials at Risk – Same Old, Same Old?
Next Post: The Congressional Budget Office Was Hacked. It Says It Has Implemented New Security Measures

Related Posts

OpenAI Unveils Enhanced ChatGPT Security Feature OpenAI Unveils Enhanced ChatGPT Security Feature Security Week News
PwC and Google Cloud Ink 0 Million Deal to Scale AI-Powered Defense PwC and Google Cloud Ink $400 Million Deal to Scale AI-Powered Defense Security Week News
Cisco Patches Zero-Day Flaw Affecting Routers and Switches Cisco Patches Zero-Day Flaw Affecting Routers and Switches Security Week News
Android’s December 2025 Updates Patch Two Zero-Days Android’s December 2025 Updates Patch Two Zero-Days Security Week News
Tech Alliance ‘Athena’ Secures Open Source Software Tech Alliance ‘Athena’ Secures Open Source Software Security Week News
263,000 Impacted by Esse Health Data Breach 263,000 Impacted by Esse Health Data Breach Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • AI-Powered Cyberattack Targets Taiwan Government
  • Ivanti EPM Update Resolves Critical Security Flaws
  • Adobe ColdFusion Flaws Pose Severe Security Risks
  • WhatsApp Introduces Scam Alert to Enhance Security
  • Enterprise Security Shows Strength at Edge, Weakness Within

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • AI-Powered Cyberattack Targets Taiwan Government
  • Ivanti EPM Update Resolves Critical Security Flaws
  • Adobe ColdFusion Flaws Pose Severe Security Risks
  • WhatsApp Introduces Scam Alert to Enhance Security
  • Enterprise Security Shows Strength at Edge, Weakness Within

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark