{"id":8893,"date":"2025-12-03T10:03:34","date_gmt":"2025-12-03T10:03:34","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/12\/03\/chrome-143-released-with-fix-for-13-vulnerabilities-that-enable-arbitrary-code-execution\/"},"modified":"2025-12-03T10:03:34","modified_gmt":"2025-12-03T10:03:34","slug":"chrome-143-released-with-fix-for-13-vulnerabilities-that-enable-arbitrary-code-execution","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/12\/03\/chrome-143-released-with-fix-for-13-vulnerabilities-that-enable-arbitrary-code-execution\/","title":{"rendered":"Chrome 143 Released With Fix for 13 Vulnerabilities that Enable Arbitrary Code Execution"},"content":{"rendered":"<p>    Chrome 143 Released With Fix for 13 Vulnerabilities that Enable Arbitrary Code Execution<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>Google has officially promoted Chrome 143 to the Stable channel, rolling out version 143.0.7499.40 for Linux and 143.0.7499.40\/41 for Windows and Mac.<\/p>\n<p>This significant update addresses 13 security vulnerabilities, including several high-severity flaws that could allow attackers to execute arbitrary code or compromise the browser\u2019s rendering engine.<\/p>\n<p>The most critical vulnerability addressed in this release is CVE-2025-13630, a <a href=\"https:\/\/cybersecuritynews.com\/chrome-type-confusion-zero-day\/\" target=\"_blank\" rel=\"noreferrer noopener\">Type Confusion vulnerability<\/a> in the V8 JavaScript engine. Reported by security researcher Shreyas Penkar, this flaw earned a bounty of $11,000.<\/p>\n<p>Type confusion vulnerabilities are particularly dangerous because they occur when the program allocates a resource using one type but subsequently accesses it using a different, incompatible type.<\/p>\n<p>In a browser context, successful exploitation of a V8 type confusion bug often allows a remote attacker to execute arbitrary code inside the renderer sandbox by tricking the user into visiting a specially crafted website.<\/p>\n<p>Another notable high-severity issue is CVE-2025-13631, an inappropriate implementation flaw in the Google Updater service. This vulnerability was reported by researcher Jota Domingos and carried a $3,000 reward.<\/p>\n<p>While specific details regarding the exploitation vector remain restricted to prevent widespread abuse, <a href=\"https:\/\/cybersecuritynews.com\/defending-against-owasp-top-10-vulnerabilities\/\" target=\"_blank\" rel=\"noreferrer noopener\">vulnerabilities<\/a> in update mechanisms can sometimes be leveraged to establish persistence or elevate privileges on a host system.<\/p>\n<p>The update also resolves CVE-2025-13632, a high-severity issue in DevTools reported by Leandro Teles, and CVE-2025-13633, a \u201cUse After Free\u201d (UAF) memory corruption bug in Digital Credentials discovered internally by Google.<\/p>\n<p>UAF bugs remain a typical class of memory-safety errors in Chrome, often occurring when the browser attempts to use freed memory, leading to crashes or potential code execution.<\/p>\n<p>Google has restricted access to the <a href=\"https:\/\/chromereleases.googleblog.com\/2025\/12\/stable-channel-update-for-desktop.html\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">full bug details<\/a> until a majority of the user base has updated to the patched version. This standard operating procedure minimizes the risk of threat actors reverse-engineering the patch to develop exploits for unpatched browsers.<\/p>\n<p>The following table summarizes the key external security contributions resolved in Chrome 143:<\/p>\n<figure class=\"wp-block-table is-style-stripes\">\n<table class=\"has-fixed-layout\">\n<thead>\n<tr>\n<th>CVE ID<\/th>\n<th>Severity<\/th>\n<th>Vulnerability Type<\/th>\n<th>Component<\/th>\n<th>Reward<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>CVE-2025-13630<\/td>\n<td>High<\/td>\n<td>Type Confusion<\/td>\n<td>V8<\/td>\n<td>$11,000<\/td>\n<\/tr>\n<tr>\n<td>CVE-2025-13631<\/td>\n<td>High<\/td>\n<td>Inappropriate Implementation<\/td>\n<td>Google Updater<\/td>\n<td>$3,000<\/td>\n<\/tr>\n<tr>\n<td>CVE-2025-13632<\/td>\n<td>High<\/td>\n<td>Inappropriate Implementation<\/td>\n<td>DevTools<\/td>\n<td>TBD<\/td>\n<\/tr>\n<tr>\n<td>CVE-2025-13634<\/td>\n<td>Medium<\/td>\n<td>Inappropriate Implementation<\/td>\n<td>Downloads<\/td>\n<td>TBD<\/td>\n<\/tr>\n<tr>\n<td>CVE-2025-13635<\/td>\n<td>Low<\/td>\n<td>Inappropriate Implementation<\/td>\n<td>Downloads<\/td>\n<td>$3,000<\/td>\n<\/tr>\n<tr>\n<td>CVE-2025-13636<\/td>\n<td>Low<\/td>\n<td>Inappropriate Implementation<\/td>\n<td>Split View<\/td>\n<td>$1,000<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/figure>\n<p>Beyond the external reports, Google\u2019s internal security team identified several other issues, including a medium-severity race condition in V8 (CVE-2025-13721) and a bad cast in the Loader component (CVE-2025-13720)<\/p>\n<p> The Chrome team utilized automated testing tools such as AddressSanitizer and libFuzzer to detect these memory variances during the development cycle.<\/p>\n<p>Users on Windows, Mac, and Linux should look for the update to install automatically over the coming days. Manual checks can be performed by navigating to the Chrome menu, selecting Help, and clicking About Google Chrome to force the download of version 143.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 94%,rgb(169,184,195) 100%)\"><strong>Follow us on <a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>, <a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>, and <a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">X<\/a> for daily cybersecurity updates. <a href=\"https:\/\/cybersecuritynews.com\/contact-us\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Contact us<\/a> to feature your stories.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/chrome-143-released\/\">Chrome 143 Released With Fix for 13 Vulnerabilities that Enable Arbitrary Code Execution<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Guru Baran<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/chrome-143-released\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Chrome 143 Released With Fix for 13 Vulnerabilities that Enable Arbitrary Code Execution Google has officially promoted Chrome 143 to the Stable channel, rolling out version 143.0.7499.40 for Linux and 143.0.7499.40\/41 for Windows and Mac. This significant update addresses 13 security vulnerabilities, including several high-severity flaws that could allow attackers to execute arbitrary code or [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,131,648],"tags":[130],"class_list":["post-8893","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-vulnerability","category-vulnerability-news","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/8893"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=8893"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/8893\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=8893"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=8893"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=8893"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}