{"id":8053,"date":"2025-10-30T10:03:35","date_gmt":"2025-10-30T10:03:35","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/10\/30\/chrome-142-released-with-fix-for-20-vulnerabilities-that-allows-malicious-code-execution\/"},"modified":"2025-10-30T10:03:35","modified_gmt":"2025-10-30T10:03:35","slug":"chrome-142-released-with-fix-for-20-vulnerabilities-that-allows-malicious-code-execution","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/10\/30\/chrome-142-released-with-fix-for-20-vulnerabilities-that-allows-malicious-code-execution\/","title":{"rendered":"Chrome 142 Released With Fix for 20 Vulnerabilities that Allows Malicious Code Execution"},"content":{"rendered":"<p>    Chrome 142 Released With Fix for 20 Vulnerabilities that Allows Malicious Code Execution<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>Google has officially promoted Chrome 142 to the stable channel, delivering critical security updates for Windows, Mac, and Linux users. <\/p>\n<p>The rollout begins immediately and will continue over the next few days or weeks, ensuring widespread protection against newly discovered threats. <\/p>\n<p>This version addresses 20 <a href=\"https:\/\/cybersecuritynews.com\/owasp-top-10\/\" target=\"_blank\" rel=\"noreferrer noopener\">vulnerabilities<\/a>, many of which could enable attackers to execute malicious code remotely, potentially compromising user data and system integrity.<\/p>\n<p>The update underscores Google\u2019s commitment to rapid response in the face of evolving browser-based attacks.<\/p>\n<p>Chrome 142.0.7444.59 for Linux, 142.0.7444.59\/60 for Windows, and 142.0.7444.60 for Mac incorporate a range of fixes and performance improvements. <\/p>\n<p>Detailed change logs are available through Chromium\u2019s source repository, highlighting enhancements in rendering, stability, and user interface. <\/p>\n<p>While full details on new features will appear in upcoming posts on the Chrome and Chromium blogs, the immediate priority is bolstering defenses against exploitation attempts. <\/p>\n<p>Security experts recommend users enable automatic updates to mitigate risks promptly, as unpatched browsers remain prime targets for cybercriminals.<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-chrome-142-released-fix-for-20-vulnerabilities\">\n<strong>Chrome 142 Released<\/strong> <strong>\u2013 Fix for 20 Vulnerabilities<\/strong><br \/>\n<\/h2>\n<p>The update addresses a wide range of vulnerabilities, including 20 security patches. Details about the bugs will initially remain confidential to allow for global deployment and to prevent facilitating active exploits.<\/p>\n<p>Several fixes arise from external researchers, earning bounties under Google\u2019s <a href=\"https:\/\/cybersecuritynews.com\/security-champions-program\/\" target=\"_blank\" rel=\"noreferrer noopener\">Vulnerability Reward Program<\/a>, while others result from internal audits and fuzzing tools like AddressSanitizer and libFuzzer.<\/p>\n<p>High-severity issues dominate, particularly in the V8 JavaScript engine, where type confusion, race conditions, and inappropriate implementations could lead to arbitrary code execution. <\/p>\n<p>Media handling and extensions also receive attention, closing gaps that might allow unauthorized access or policy bypasses. Lower-severity fixes address UI inconsistencies and storage races, preventing subtle but persistent risks.<\/p>\n<p>For a breakdown of key externally reported vulnerabilities, see the table below:<\/p>\n<figure class=\"wp-block-table\">\n<table class=\"has-fixed-layout\">\n<thead>\n<tr>\n<th>CVE ID<\/th>\n<th>Severity<\/th>\n<th>Description<\/th>\n<th>Reporter<\/th>\n<th>Bounty<\/th>\n<th>Report Date<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>CVE-2025-12428<\/td>\n<td>High<\/td>\n<td>\n<a href=\"https:\/\/cybersecuritynews.com\/google-chrome-type-confusion-vulnerability\/\" target=\"_blank\" rel=\"noreferrer noopener\">Type Confusion<\/a> in V8<\/td>\n<td>Man Yue Mo (GitHub Security Lab)<\/td>\n<td>$50,000<\/td>\n<td>2025-09-26<\/td>\n<\/tr>\n<tr>\n<td>CVE-2025-12429<\/td>\n<td>High<\/td>\n<td>Inappropriate implementation in V8<\/td>\n<td>Aorui Zhang<\/td>\n<td>$50,000<\/td>\n<td>2025-10-10<\/td>\n<\/tr>\n<tr>\n<td>CVE-2025-12430<\/td>\n<td>High<\/td>\n<td>Object lifecycle issue in Media<\/td>\n<td>round.about<\/td>\n<td>$10,000<\/td>\n<td>2025-09-04<\/td>\n<\/tr>\n<tr>\n<td>CVE-2025-12431<\/td>\n<td>High<\/td>\n<td>Inappropriate implementation in Extensions<\/td>\n<td>Alesandro Ortiz<\/td>\n<td>$4,000<\/td>\n<td>2025-08-06<\/td>\n<\/tr>\n<tr>\n<td>CVE-2025-12432<\/td>\n<td>High<\/td>\n<td>Race in V8<\/td>\n<td>Google Big Sleep<\/td>\n<td>N\/A<\/td>\n<td>2025-08-18<\/td>\n<\/tr>\n<tr>\n<td>CVE-2025-12433<\/td>\n<td>High<\/td>\n<td>Inappropriate implementation in V8<\/td>\n<td>Google Big Sleep<\/td>\n<td>N\/A<\/td>\n<td>2025-10-07<\/td>\n<\/tr>\n<tr>\n<td>CVE-2025-12036<\/td>\n<td>High<\/td>\n<td>Inappropriate implementation in V8<\/td>\n<td>Google Big Sleep<\/td>\n<td>N\/A<\/td>\n<td>2025-10-15<\/td>\n<\/tr>\n<tr>\n<td>CVE-2025-12434<\/td>\n<td>Medium<\/td>\n<td>Race in Storage<\/td>\n<td>Lijo A.T<\/td>\n<td>$3,000<\/td>\n<td>2024-04-27<\/td>\n<\/tr>\n<tr>\n<td>CVE-2025-12435<\/td>\n<td>Medium<\/td>\n<td>Incorrect security UI in Omnibox<\/td>\n<td>Hafiizh<\/td>\n<td>$3,000<\/td>\n<td>2025-09-21<\/td>\n<\/tr>\n<tr>\n<td>CVE-2025-12436<\/td>\n<td>Medium<\/td>\n<td>Policy bypass in Extensions<\/td>\n<td>Luan Herrera (@lbherrera_)<\/td>\n<td>$2,000<\/td>\n<td>2021-02-08<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/figure>\n<p>(Additional medium and low-severity fixes include <a href=\"https:\/\/cybersecuritynews.com\/use-after-free-vulnerability\/\" target=\"_blank\" rel=\"noreferrer noopener\">use-after-free<\/a> errors in PageInfo and Ozone, out-of-bounds reads in V8 and WebXR, and UI issues in Autofill, Fullscreen, and SplitView, reported by researchers like Umar Farooq, Wei Yuan, and Khalil Zhani.)<\/p>\n<p>Google extends thanks to contributors who helped squash these bugs before they hit production. Internal efforts, including fuzzing and sanitizer tools, accounted for numerous fixes, preventing a wide array of potential exploits.<\/p>\n<p>As browser usage surges amid rising phishing and malware campaigns, this release reinforces Chrome\u2019s position as a secure default for billions. Users should verify updates via chrome:\/\/settings\/help to stay protected.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 94%,rgb(169,184,195) 100%)\"><strong>Follow us on <a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>, <a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>, and <a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">X<\/a> for daily cybersecurity updates. <a href=\"https:\/\/cybersecuritynews.com\/contact-us\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Contact us<\/a> to feature your stories.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/chrome-142-released-fix-20-vulnerabilities\/\">Chrome 142 Released With Fix for 20 Vulnerabilities that Allows Malicious Code Execution<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Guru Baran<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/chrome-142-released-fix-20-vulnerabilities\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Chrome 142 Released With Fix for 20 Vulnerabilities that Allows Malicious Code Execution Google has officially promoted Chrome 142 to the stable channel, delivering critical security updates for Windows, Mac, and Linux users. The rollout begins immediately and will continue over the next few days or weeks, ensuring widespread protection against newly discovered threats. This [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,416,131],"tags":[130],"class_list":["post-8053","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-vulnerabilities","category-vulnerability","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/8053"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=8053"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/8053\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=8053"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=8053"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=8053"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}