{"id":4716,"date":"2025-06-18T10:03:36","date_gmt":"2025-06-18T10:03:36","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/06\/18\/chrome-vulnerabilities-let-attackers-execute-arbitrary-code-update-now\/"},"modified":"2025-06-18T10:03:36","modified_gmt":"2025-06-18T10:03:36","slug":"chrome-vulnerabilities-let-attackers-execute-arbitrary-code-update-now","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/06\/18\/chrome-vulnerabilities-let-attackers-execute-arbitrary-code-update-now\/","title":{"rendered":"Chrome Vulnerabilities Let Attackers Execute Arbitrary Code \u2013 Update Now!"},"content":{"rendered":"<p>    Chrome Vulnerabilities Let Attackers Execute Arbitrary Code \u2013 Update Now!<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>Google has released an urgent security update for Chrome browsers across all desktop platforms, addressing critical vulnerabilities that could allow attackers to execute arbitrary code on users\u2019 systems.\u00a0<\/p>\n<p>The update, rolled out on Tuesday, June 17, 2025, patches three significant security flaws including two high-severity vulnerabilities that earned external researchers substantial bounty rewards totaling $11,000.<\/p>\n<p>The latest Chrome Stable Channel update version 137.0.7151.119\/.120 for <a href=\"https:\/\/cybersecuritynews.com\/lazarus-hackers-exploit-windows-and-macos-users\/\" target=\"_blank\" rel=\"noreferrer noopener\">Windows and Mac<\/a>, and 137.0.7151.119 for Linux, addresses three critical security vulnerabilities that pose significant risks to user safety.\u00a0<\/p>\n<h2 class=\"wp-block-heading\"><strong>CVE-2025-6191: Integer Overflow in V8<\/strong><\/h2>\n<p>The high-severity vulnerability, tracked as CVE-2025-6191, represents an integer overflow in V8, Chrome\u2019s JavaScript engine.\u00a0<\/p>\n<p>This flaw was discovered by security researcher Shaheen Fazim on May 27, 2025, and earned a $7,000 bounty reward from Google\u2019s Vulnerability Reward Program.\u00a0<\/p>\n<p>Particularly, the vulnerability affects Chrome\u2019s core JavaScript processing engine, which handles billions of operations daily across <a href=\"https:\/\/cybersecuritynews.com\/hackers-abuse-cobalt-strike-sqlmap-other-tools\/\" target=\"_blank\" rel=\"noreferrer noopener\">web applications<\/a>.\u00a0<\/p>\n<p>Integer overflow vulnerabilities in JavaScript engines are particularly dangerous as they can lead to memory corruption and enable attackers to execute malicious code within the browser\u2019s sandbox environment.<\/p>\n<h2 class=\"wp-block-heading\"><strong>CVE-2025-6192: Use After Free in Profiler<\/strong><\/h2>\n<p>The second high-severity vulnerability, CVE-2025-6192, involves a use-after-free condition in Chrome\u2019s Profiler component.\u00a0<\/p>\n<p>Reported by researcher Chaoyuan Peng (@ret2happy) on May 31, 2025, this vulnerability earned a $4,000 reward.\u00a0<\/p>\n<p>The vulnerability targets Chrome\u2019s performance profiling system, which developers and power users often employ for debugging and optimization.\u00a0<\/p>\n<p><a href=\"https:\/\/cybersecuritynews.com\/chrome-uaf-vulnerabilities-exploited\/\" target=\"_blank\" rel=\"noreferrer noopener\">Use-after-free vulnerabilities<\/a> occur when a program continues to use memory after it has been freed, potentially allowing attackers to manipulate memory contents and achieve code execution.<\/p>\n<p>Google\u2019s security team emphasizes that access to detailed bug information remains restricted until the majority of users have updated their browsers.\u00a0<\/p>\n<p>The company also <a href=\"https:\/\/chromereleases.googleblog.com\/2025\/06\/stable-channel-update-for-desktop_17.html\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">noted<\/a> that restrictions may remain in place if the vulnerabilities affect third-party libraries used by other projects that haven\u2019t yet implemented fixes.<\/p>\n<h2 class=\"wp-block-heading\"><strong>Immediate Action Required for Users<\/strong><\/h2>\n<p>Chrome users across all desktop platforms must update immediately to protect against potential exploitation of these vulnerabilities.\u00a0<\/p>\n<p>The update rollout began Tuesday and will continue over the coming days and weeks through Chrome\u2019s automatic update mechanism.\u00a0<\/p>\n<p>Users can manually check for updates by navigating to Chrome Settings &gt; About Chrome or by accessing chrome:\/\/settings\/help in their browser\u2019s address bar.<\/p>\n<p>The rapid response to these vulnerabilities demonstrates the critical importance of maintaining updated browser software and highlights the ongoing security challenges facing modern <a href=\"https:\/\/cybersecuritynews.com\/t1555-003-technique-steal-passwords\/\" target=\"_blank\" rel=\"noreferrer noopener\">web browsers<\/a> as they balance functionality with user protection.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 93%,rgb(169,184,195) 100%)\"><strong><strong>Power up early threat detection, escalation, and mitigation with ANY.RUN\u2019s Threat Intelligence Lookup. <\/strong><a href=\"https:\/\/intelligence.any.run\/plans\/?utm_source=csn_jun&amp;utm_medium=article&amp;utm_campaign=how-to-detect-threats-early-for-fast-incident-response&amp;utm_content=plans&amp;utm_term=170625\" target=\"_blank\" rel=\"noreferrer noopener nofollow\"><strong>Get 50 trial searches<\/strong><\/a><strong>.<\/strong><\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/chrome-vulnerabilities-update-now\/\">Chrome Vulnerabilities Let Attackers Execute Arbitrary Code \u2013 Update Now!<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Guru Baran<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/chrome-vulnerabilities-update-now\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Chrome Vulnerabilities Let Attackers Execute Arbitrary Code \u2013 Update Now! Google has released an urgent security update for Chrome browsers across all desktop platforms, addressing critical vulnerabilities that could allow attackers to execute arbitrary code on users\u2019 systems.\u00a0 The update, rolled out on Tuesday, June 17, 2025, patches three significant security flaws including two high-severity [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,652,416,131],"tags":[130],"class_list":["post-4716","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-security-news","category-vulnerabilities","category-vulnerability","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/4716"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=4716"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/4716\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=4716"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=4716"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=4716"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}