Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
endpoint-software-vulnerabilitywidely-deployed-product-advisoryinternet-facing-service-vulnerability

Google Chrome and Chromium Browsers Patched for Multiple Security Vulnerabilities Including WebXR Data Leak

Updated 3mo agoFirst seen Dec 4, 20253 sources

Google has released a security update for its Chrome browser, addressing 13 vulnerabilities, four of which are rated high severity. Among the most notable is a use-after-free flaw in the Digital Credentials feature (CVE-2025-13633), which could allow remote attackers to exploit affected systems. The update brings Chrome to version 143.0.7499.40/.41 for Windows and macOS, and 143.0.7499.40 for Linux, and users are strongly advised to update promptly to mitigate risk, as attackers often exploit such vulnerabilities before widespread patch adoption.

In addition to the Digital Credentials issue, a significant data leak vulnerability was discovered in the WebXR component (CVE-2025-12443), affecting all major Chromium-based browsers, including Chrome, Edge, Brave, and Opera. The flaw, which could expose heap memory and pointer data, required user interaction with a malicious page to be exploited. Google responded rapidly to the responsible disclosure, issuing a fix within 24 hours and updating the stable Chrome release within two weeks. Users of all Chromium-based browsers are urged to update to the latest versions to ensure protection against these and other recently patched vulnerabilities.

Share:
Google Chrome and Chromium Browsers Patched for Multiple Security Vulnerabilities Including WebXR Data Leak
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

6 events from the most recent confirmed update back to the earliest known activity.

6 EVENTS
Dec 4, 20257mo ago

Google patches high-severity Digital Credentials bug

Among the Chrome 143 fixes, Google addressed CVE-2025-13633, a high-severity use-after-free vulnerability in the Digital Credentials feature affecting Chrome versions prior to 143.0.7499.41. Google withheld detailed technical information until more users had updated.

Google releases Chrome 143 with 13 security fixes

Google released Chrome 143 in early December 2025, fixing 13 security issues including four rated high severity, and urged users to update promptly because of Chrome's massive user base.

Oct 14, 20258mo ago

Chrome 142 update ships with WebXR vulnerability fix

Within 13 days of the WebXR flaw's disclosure, Google updated Chrome to version 142.0.7444.59 to address CVE-2025-12443 and reduce exposure across billions of Chromium users.

Oct 2, 20259mo ago

Google fixes WebXR flaw within 24 hours of disclosure

Google responded to disclosure of CVE-2025-12443 by producing a fix within 24 hours, beginning remediation for affected Chromium-based browsers including Chrome and other downstream projects.

Oct 1, 20259mo ago

AISLE discovers Chromium WebXR flaw

In October 2025, researcher AISLE discovered CVE-2025-12443, a medium-severity vulnerability in Chromium's WebXR component that could leak 64 bytes of adjacent heap memory when a user interacted with a malicious VR or AR session.

Mar 1, 20251y ago

WebXR vulnerability introduced into Chromium codebase

The WebXR flaw later tracked as CVE-2025-12443 had reportedly been present in Chromium for about seven months before it was discovered, exposing affected Chromium-based browsers to potential memory leakage during crafted VR or AR sessions.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

10 LINKEDOpen in app
Affected products
2 linked
Brave BrowserOpera Browser
Organizations
7 linked
Microsoft CorporationGoogleBrave SoftwareOperaChromium ProjectEdge GroupAISLE
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

Google Chrome and Chromium Browsers Patched for Multiple Security Vulnerabilities Including WebXR Data Leak | Mallory