2025-03-21
Chrome Update Addresses Critical Use-After-Free Vulnerability
Chrome stable channel for desktop has been updated to version 134.0.6998.117/.118 for Windows and Mac, and 134.0.6998.117 for Linux. The newest version of Google's browser includes a fix for a critical use-after-free flaw in Lens that could be exploited to crash the browser or infect a vulnerable computer with malware. The flaw can be exploited by 'a remote attacker to potentially exploit heap corruption via a crafted HTML page.' The updates will roll out over a period of several days.
Editor's Note
CVE-2025-2476, use after free in Google Lens, CVSS score 8.8, is addressed in 134.0.6998.117/.118 and the current stable update for desktop is now 134.0.6998.165/.166, released March 21st, also has the fix. This is also the base version for your other Chromium browsers like Brave, Opera, etc. It's getting to the point where you want to make sure you've updated/restarted browsers weekly to keep them current; fortunately they are a lot better at picking up where they left when restarted. If you're allowing users to restart to apply the update when convenient, be sure to put an upper limit on the grace period, like 48 or 72 hours.
