Google rolls out emergency Chrome update to patch actively exploited flaw

Google rolls out emergency Chrome update to patch actively exploited flaw

Google released an out-of-band security update for its Chrome browser, addressing three vulnerabilities, including a high-severity zero-day flaw that is being actively exploited in the wild.

The critical vulnerability, tracked as CVE-2025-5419 is described as an out-of-bounds read and write issue in Chrome’s V8 JavaScript and WebAssembly engine. The flaw could allow attackers to corrupt memory on the heap via specially crafted HTML pages, potentially leading to remote code execution. The bug affects Chrome versions prior to 137.0.7151.68.

"Google is aware that an exploit for CVE-2025-5419 exists in the wild," the company said in its advisory, though it withheld specifics about the attacks or the threat actors involved to prevent further exploitation.

This marks the second Chrome zero-day exploited in the wild this year, following CVE-2025-2783, which was previously used in attacks targeting entities in Russia.

Users are strongly advised to update to Chrome version 137.0.7151.68 or 137.0.7151.69 on Windows and macOS, and 137.0.7151.68 on Linux. Users of Chromium-based browsers, including Microsoft Edge, Brave, Opera, and Vivaldi, should also apply the updates as soon as they become available.


Back to the list

Latest Posts

Cyber Security Week in Review: June 20, 2025

Cyber Security Week in Review: June 20, 2025

In brief: the Langflow, TP-Link and Zyxel flaws exploited in the wild, Russian hackers use ASPs to infiltrate victims’ email accounts, and more
20 June 2025
Russian-linked hackers exploit Google App passwords in email espionage campaign

Russian-linked hackers exploit Google App passwords in email espionage campaign

Victims were tricked into creating and sharing ASPs under the mistaken belief that they are enabling secure communication with the US Department of State.
19 June 2025
FBI-wanted member of ransomware gang arrested in Ukraine, extradited to the US

FBI-wanted member of ransomware gang arrested in Ukraine, extradited to the US

Using custom-developed malware, including ransomware such as LockerGoga, MegaCortex, HIVE and Dharma, the hackers encrypted data on corporate networks.
18 June 2025