Chrome for Android Update
Hi, everyone! We've just released Chrome 139 (139.0.7258.123) for Android. It'll become available on Google Play over the next few days.
This release includes stability and performance improvements. You can see a full list of the changes in the Git log. If you find a new issue, please let us know by filing a bug.
Google Chrome
Source: Google Chrome Releases
Extended Stable Updates for Desktop
The Extended Stable channel has been updated to 138.0.7204.235 for Windows and Mac which will roll out over the coming days/weeks.
Source: Google Chrome Releases
Stable Channel Update for Desktop
The Stable channel has been updated to 139.0.7258.127/.128 for Windows, Mac and 139.0.7258.127 for Linux which will roll out over the coming days/weeks. A full list of changes in this build is available in the Log.
Security Fixes and Rewards
Note: Access to bug details and links may be kept restricted until a majority of users are updated with a fix. We will also retain restrictions if the bug exists in a third party library that other projects similarly depend on, but haven’t yet fixed
This update includes 6 security fixes. Below, we highlight fixes that were contributed by external researchers. Please see the Chrome Security Page for more information
As usual, our ongoing internal security work was responsible for a wide range of fixes:
[TBD][432035817] High CVE-2025-8879: Heap buffer overflow in libaom. Reported by Anonymous on 2025-07-15
[TBD][433533359] High CVE-2025-8880: Race in V8. Reported by Seunghyun Lee (@0x10n) on 2025-07-23
[N/A][435139154] High CVE-2025-8901: Out of bounds write in ANGLE. Reported by Google Big Sleep on 2025-07-30
[TBD][433800617] Medium CVE-2025-8881: Inappropriate implementation in File Picker. Reported by Alesandro Ortiz on 2025-07-23
[TBD][435623339] Medium CVE-2025-8882: Use after free in Aura. Reported by Umar Farooq on 2025-08-01
We would also like to thank all security researchers that worked with us during the development cycle to prevent security bugs from ever reaching the stable channel.
[438094852] Various fixes from internal audits, fuzzing and other initiatives
Many of our security bugs are detected using AddressSanitizer, MemorySanitizer, UndefinedBehaviorSanitizer, Control Flow Integrity, libFuzzer, or AFL.
Interested in switching release channels? Find out how here. If you find a new issue, please let us know by filing a bug. The community help forum is also a great place to reach out for help or learn about common issues.
Google Chrome
Source: Google Chrome Releases
Long Term Support Channel Update for ChromeOS
A new LTC version 138.0.7204.221 (Platform Version: 16295.70.0), is being rolled out for most ChromeOS devices.
Giuliana Pritchard
Google Chrome OS
Source: Google Chrome Releases
Android’s pKVM Becomes First Globally Certified Software to Achieve Prestigious SESIP Level 5 Security Certification
Today marks a watershed moment and new benchmark for open-source security and the future of consumer electronics. Google is proud to announce that protected KVM (pKVM), the hypervisor that powers the Android Virtualization Framework, has officially achieved SESIP Level 5 certification. This makes pKVM the first software security system designed for large-scale deployment in consumer electronics to meet this assurance bar.
Supporting Next-Gen Android Features
The implications for the future of secure mobile technology are profound. With this level of security assurance, Android is now positioned to securely support the next generation of high-criticality isolated workloads. This includes vital features, such as on-device AI workloads that can operate on ultra-personalized data, with the highest assurances of privacy and integrity.
This certification required a hands-on evaluation by Dekra, a globally recognized cybersecurity certification lab, which conducted an evaluation against the TrustCB SESIP scheme, compliant to EN-17927. Achieving Security Evaluation Standard for IoT Platforms (SESIP) Level 5 is a landmark because it incorporates AVA_VAN.5, the highest level of vulnerability analysis and penetration testing under the ISO 15408 (Common Criteria) standard. A system certified to this level has been evaluated to be resistant to highly skilled, knowledgeable, well-motivated, and well-funded attackers who may have insider knowledge and access.
This certification is the cornerstone of the next-generation of Android’s multi-layered security strategy. Many of the TEEs (Trusted Execution Environments) used in the industry have not been formally certified or have only achieved lower levels of security assurance. This inconsistency creates a challenge for developers looking to build highly critical applications that require a robust and verifiable level of security. The certified pKVM changes this paradigm entirely. It provides a single, open-source, and exceptionally high-quality firmware base that all device manufacturers can build upon.
Looking ahead, Android device manufacturers will be required to use isolation technology that meets this same level of security for various security operations that the device relies on. Protected KVM ensures that every user can benefit from a consistent, transparent, and verifiably secure foundation.
A Collaborative Effort
This achievement represents just one important aspect of the immense, multi-year dedication from the Linux and KVM developer communities and multiple engineering teams at Google developing pKVM and AVF. We look forward to seeing the open-source community and Android ecosystem continue to build on this foundation, delivering a new era of high-assurance mobile technology for users.
Source: Google Online Security Blog
How to select your preferred sources in Top Stories in Search
Preferred Sources is available starting today for all users in the U.S. and India.
Source: Search
How we’re using AI in new ways to fight invalid traffic
An overview of our latest efforts to provide even better protections against invalid ad traffic by using AI.
Source: Google Ads & Commerce
We’re adding 3 new ways to make web payments easier and more flexible.
Today, we’re sharing new ways we’re giving online shoppers added choice, convenience, and value — whether it’s for an everyday purchase, a big-ticket item or an internat…
Source: The Official Google Blog
Adding NotebookLM and Gems to Gemini Learning Tools Interoperability (LTI™)
What’s changing
- Create content-grounded Notebooks that help define their curriculum and empower students to learn at their own pace.
- Create Gems for FAQs that help students quickly find answers to common questions about assignments, and more.
- Learn on-the-go by creating a podcast-like Audio Overview of their course material with NotebookLM
- Get in-the-moment assistance with real-time coaching using Gems.
Who’s impacted
Additional details
Getting started
- Admins:
- In order for educators and students to access the Gemini LTI™, you’ll need to enable Google Workspace LTI™ service in Admin Console and enable Gemini service in Admin Console. Visit the Help Center to learn more about Gemini LTI in general.
- Learning Management Systems admins need to enable Gemini LTI™ in their LMS as well. Visit the Help Center to learn more about setting up Gemini LTI in Canvas by Instructure and Powerschool Schoology Learning.
- End users:
- Visit the Help Center to learn more about Gemini LTI.
Rollout pace
- Rapid Release and Scheduled Release domains: Gradual rollout (up to 15 days for feature visibility) starting on August 4, 2025
Availability
- Education Fundamentals, Standard, and Plus
- Customers with the Gemini Education or Gemini Education Premium add-on
Resources
- Google Workspace Admin Help: Learn how to turn on Google Workspace LTI™
- Google Workspace Admin Help: Turn the Gemini app on or off
- Google Workspace Admin Help: Set up Assignments LTI™/Drive LTI™ in Canvas
- Google Help: Google Workspace LTI™ overview

