Google has released a security update for its Chrome browser, addressing 13 vulnerabilities, four of which are rated high severity. Among the most notable is a use-after-free flaw in the Digital Credentials feature (CVE-2025-13633), which could allow remote attackers to exploit affected systems. The update brings Chrome to version 143.0.7499.40/.41 for Windows and macOS, and 143.0.7499.40 for Linux, and users are strongly advised to update promptly to mitigate risk, as attackers often exploit such vulnerabilities before widespread patch adoption.
In addition to the Digital Credentials issue, a significant data leak vulnerability was discovered in the WebXR component (CVE-2025-12443), affecting all major Chromium-based browsers, including Chrome, Edge, Brave, and Opera. The flaw, which could expose heap memory and pointer data, required user interaction with a malicious page to be exploited. Google responded rapidly to the responsible disclosure, issuing a fix within 24 hours and updating the stable Chrome release within two weeks. Users of all Chromium-based browsers are urged to update to the latest versions to ensure protection against these and other recently patched vulnerabilities.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
6 events from the most recent confirmed update back to the earliest known activity.
Among the Chrome 143 fixes, Google addressed CVE-2025-13633, a high-severity use-after-free vulnerability in the Digital Credentials feature affecting Chrome versions prior to 143.0.7499.41. Google withheld detailed technical information until more users had updated.
Google released Chrome 143 in early December 2025, fixing 13 security issues including four rated high severity, and urged users to update promptly because of Chrome's massive user base.
Within 13 days of the WebXR flaw's disclosure, Google updated Chrome to version 142.0.7444.59 to address CVE-2025-12443 and reduce exposure across billions of Chromium users.
Google responded to disclosure of CVE-2025-12443 by producing a fix within 24 hours, beginning remediation for affected Chromium-based browsers including Chrome and other downstream projects.
In October 2025, researcher AISLE discovered CVE-2025-12443, a medium-severity vulnerability in Chromium's WebXR component that could leak 64 bytes of adjacent heap memory when a user interacted with a malicious VR or AR session.
The WebXR flaw later tracked as CVE-2025-12443 had reportedly been present in Chromium for about seven months before it was discovered, exposing affected Chromium-based browsers to potential memory leakage during crafted VR or AR sessions.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
techrepublic.com
Open sourcemalwarebytes.com
Open sourcehackread.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.