High-Severity Chrome Vulnerabilities Expose Users to Arbitrary Code Execution

Google Chrome has released version 138.0.7204.168 across multiple platforms, delivering essential security fixes and performance improvements to billions of users worldwide.

This latest stable channel update addresses critical vulnerabilities while simultaneously advancing development versions across desktop, mobile, and ChromeOS platforms, demonstrating the browser’s commitment to both security and innovation.

Stable Channel Deployment

The Chrome stable channel has been updated to version 138.0.7204.168/.169 for Windows and Mac systems, with Linux receiving build 138.0.7204.168.

This rollout will occur gradually over the coming days and weeks, following Google’s standard phased deployment methodology to ensure system stability across diverse hardware configurations.

The Android version of Chrome 138 (138.0.7204.168) has been released simultaneously and will become available through Google Play Store distribution channels over the next few days.

This release prioritizes stability and performance enhancements, with comprehensive change logs available through the official Git repository.

The engineering team has implemented various internal optimizations while maintaining backward compatibility with existing web applications and browser extensions.

Users can expect improved memory management and enhanced rendering performance across all supported operating systems.

Critical V8 Engine Vulnerabilities

The update includes three significant security fixes, with particular attention to V8 JavaScript engine vulnerabilities.

Two high-severity issues have been identified and resolved: CVE-2025-8010 and CVE-2025-8011, both classified as Type Confusion vulnerabilities in the V8 engine.

Security researcher Shaheen Fazim discovered these critical flaws on July 9, 2025, earning an $8,000 bounty for the first vulnerability.

These Type Confusion vulnerabilities could potentially allow malicious actors to execute arbitrary code through carefully crafted JavaScript, making their resolution paramount for user safety.

Google’s security infrastructure, utilizing AddressSanitizer, MemorySanitizer, UndefinedBehaviorSanitizer, Control Flow Integrity, libFuzzer, and AFL testing frameworks, continues to identify and prevent security bugs from reaching stable releases.

The company maintains restricted access to vulnerability details until widespread user adoption of the fixes occurs.

Development Channels

Chrome’s development ecosystem continues evolving with multiple channel updates.

The Dev channel has progressed to version 140.0.7299.0 for Windows, Mac, and Linux platforms, while Android Dev channel users can access Chrome 140.0.7299.0 through Google Play.

The Beta channel maintains version 139.0.7258.42 across desktop platforms, providing stability testing for upcoming features.

ChromeOS development has advanced to OS version 16328.25.0 with browser version 139.0.7258.43 across most ChromeOS devices.

This coordinated multi-platform development approach ensures feature parity and consistent user experiences across Google’s ecosystem while maintaining independent update cycles for different stability requirements.

Find this Story Interesting! Follow us on LinkedIn and X to Get More Instant Updates.

AnuPriya
AnuPriya
Any Priya is a cybersecurity reporter at Cyber Press, specializing in cyber attacks, dark web monitoring, data breaches, vulnerabilities, and malware. She delivers in-depth analysis on emerging threats and digital security trends.

Recent Articles

Related Stories

LEAVE A REPLY

Please enter your comment!
Please enter your name here