Critical Chrome Vulnerabilities Allow Attackers to Take Control of Memory and Execute Malicious Code

Google has rolled out Chrome 138 across its major platforms, bringing stability improvements and critical security fixes to billions of users worldwide.

The latest stable release represents a significant update that addresses performance issues while strengthening browser security infrastructure.

Major Platform Updates Rolling Out

Google announced the release of Chrome 138 for Android devices on July 29, 2025, with version 138.0.7204.179 becoming available on Google Play over the coming days.

This Android release focuses primarily on stability and performance improvements, continuing Google’s commitment to optimizing the mobile browsing experience for users across different device configurations.

Simultaneously, desktop users are receiving the stable channel update to version 138.0.7204.183/.184 for Windows and Mac systems, while Linux users get version 138.0.7204.183.

These updates are being distributed gradually over the coming days and weeks, following Google’s standard rollout procedure to ensure system stability and minimize potential compatibility issues.

ChromeOS devices are also receiving attention with the deployment of Chrome 138.0.7204.163, designated as a Long Term Channel (LTC) version with Platform Version 16295.54.0.

This ChromeOS release specifically targets most ChromeOS devices, ensuring that Chromebook users receive the same security and performance benefits as their desktop and mobile counterparts.

Security Enhancements and Bug Fixes

The Chrome 138 release includes four significant security fixes, with particular attention paid to vulnerabilities discovered by external security researchers.

One notable security fix addresses CVE-2025-8292, a high-severity “Use after free in Media Stream” vulnerability that earned an anonymous researcher an $8000 reward for their contribution to Chrome’s security.

Google’s ongoing internal security initiatives have also contributed to this release, with various fixes resulting from internal audits, fuzzing operations, and other security-focused programs.

The company continues to leverage advanced detection tools, including AddressSanitizer, MemorySanitizer, UndefinedBehaviorSanitizer, Control Flow Integrity, libFuzzer, and AF,L to identify and resolve potential security vulnerabilities before they reach stable releases.

Development Channel Progress

Looking ahead, Google has also updated its development channels with Chrome Dev 140.0.7312.0 for Windows, Mac, and Linux systems.

Android developers can access Chrome Dev 140.0.7313.0 through Google Play, providing early access to upcoming features and improvements.

These development releases allow web developers and early adopters to test upcoming changes and provide feedback before features reach the stable channel.

The ChromeOS development channel has advanced to OS version 16358.0.0 with Browser version 140.0.7310.0_pre1489499, continuing the platform’s evolution alongside the standard Chrome browser.

This coordinated development approach ensures consistent feature availability and security standards across Google’s entire ecosystem of Chrome-powered devices and platforms.

Find this Story Interesting! Follow us on LinkedIn and X to Get More Instant Updates

AnuPriya
AnuPriya
Any Priya is a cybersecurity reporter at Cyber Press, specializing in cyber attacks, dark web monitoring, data breaches, vulnerabilities, and malware. She delivers in-depth analysis on emerging threats and digital security trends.

Recent Articles

Related Stories

LEAVE A REPLY

Please enter your comment!
Please enter your name here