Description

Google has officially released Chrome 137 to the stable channel for Windows, Mac, and Linux platforms as of May 27, 2025. This update, version 137.0.7151.55/56, introduces major security improvements, resolving 11 vulnerabilities—several of which are classified as high severity. Notable among them are CVE-2025-5063, a use-after-free bug in Compositing, and CVE-2025-5280, an out-of-bounds write issue in the V8 JavaScript engine. These flaws could lead to code execution and compromise system integrity. The update also features bug bounty payouts for discoveries in APIs such as Background Fetch and FileSystemAccess. Google maintains its policy of responsible disclosure, withholding technical details until most users are updated. These updates are crucial because they address vulnerabilities that could be exploited by attackers to execute arbitrary code or manipulate user interactions. The release also showcases a leap in security innovation with the integration of Gemini Nano—Google’s on-device AI model. This system is specifically designed to detect and counter tech support scams by analyzing real-time webpage behavior and layout. Unlike traditional blocklists, this AI-driven approach proactively identifies threats based on behavior patterns, even if they exist only briefly. Furthermore, enhancements like floating-point canvas color support and SVG improvements aim to streamline development and increase rendering precision. Users are advised to update to Chrome 137 as soon as possible to benefit from the critical security patches and new AI-driven protection features. Developers should also explore the new web capabilities, such as Document-Isolation-Policy and Ed25519 support, to enhance app performance and security. Staying current with browser updates is essential to maintaining both user safety and optimal web experiences.