Chrome 142 Released: Two high-severity V8 flaws fixed, $100K in rewards paid
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2025-12428 | Type Confusion in V8 in Google Chrome prior to 142.0.7444.59 allowed a remote attacker to perform arbitrary read/write via a crafted HTML page. Type Confusion in V8 in Google Chrome prior to 142.0.7444.59 allowed a remote attacker to perform arbitrary read/write via a crafted HTML page. (Chromium security severity: High) NVD description · AI analysis pending | 8.8 group max | 7% |
| — |
Full article218 words · extracted from securityaffairs.com · click to collapse
Pierluigi Paganini
November 03, 2025

Google released Chrome 142, fixing 20 flaws, including two high-severity V8 bugs, and awarded $100,000 in bug bounties.
Google addressed 20 flaws in Chrome version 142, including high-severity bugs that impact the V8 engine. The IT giant awarded $100,000 in bounties for two issues in the V8 JavaScript engine.
The two vulnerabilities are tracked as CVE-2025-12428 and CVE-2025-12429.
The high-severity vulnerability CVE-2025-12428 is a type Confusion in V8. Man Yue Mo of GitHub Security Lab reported the flaw on 2025-09-26. The vulnerability was awarded $50000.
The high-severity vulnerability CVE-2025-12429 is a type Confusion in V8. Aorui Zhang reported the flaw. The vulnerability was awarded $50000.
Google also awarded $10,000 for a Media object lifecycle vulnerability, tracked as CVE-2025-12430, which was reported by round.about.
Three high-severity V8 flaws found by Google’s Big Sleep AI agent received no bug bounty rewards.
Google also resolved multiple medium-severity flaws in Omnibox, Storage, Extensions, Ozone, PageInfo, App-Bound Encryption, and V8, and low-severity flaws in Autofill, WebXR, Fullscreen UI, Extensions, and SplitView.
It is unclear whether any of these vulnerabilities are being actively exploited in the wild.
Chrome 142.0.7444.59/60 is rolling out for Linux, Windows, and macOS, with slight version differences across platforms.
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – hacking, Google)
Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/184149/security/chrome-142-released-two-high-severity-v8-flaws-fixed-100k-in-rewards-paid.html