Close Menu
geekfence.comgeekfence.com
    What's Hot

    OpenAI launches GPT-5.2 as it battles Google’s Gemini 3 for AI model supremacy – Computerworld

    December 14, 2025

    The Download: Expanded carrier screening, and how Southeast Asia plans to get to space

    December 14, 2025

    How Bayer transforms Pharma R&D with a cloud-based data science ecosystem using Amazon SageMaker

    December 14, 2025
    Facebook X (Twitter) Instagram
    • About Us
    • Contact Us
    Facebook Instagram
    geekfence.comgeekfence.com
    • Home
    • UK Tech News
    • AI
    • Big Data
    • Cyber Security
      • Cloud Computing
      • iOS Development
    • IoT
    • Mobile
    • Software
      • Software Development
      • Software Engineering
    • Technology
      • Green Technology
      • Nanotechnology
    • Telecom
    geekfence.comgeekfence.com
    Home»Cyber Security»Google fixes new Chrome zero-day flaw exploited in attacks
    Cyber Security

    Google fixes new Chrome zero-day flaw exploited in attacks

    AdminBy AdminNovember 18, 2025No Comments3 Mins Read0 Views
    Facebook Twitter Pinterest LinkedIn Telegram Tumblr Email
    Google fixes new Chrome zero-day flaw exploited in attacks
    Share
    Facebook Twitter LinkedIn Pinterest Email


    Google fixes new Chrome zero-day flaw exploited in attacks

    Google has released an emergency security update to fix the seventh Chrome zero-day vulnerability exploited in attacks this year.

    “Google is aware that an exploit for CVE-2025-13223 exists in the wild,” the search giant warned in a security advisorypublished on Monday.

    This high-severity vulnerability is caused by a type confusion weakness in Chrome’s V8 JavaScript engine, reported last week by Clement Lecigne of Google’s Threat Analysis Group. Google TAG frequently flags zero-day exploits by government-sponsored threat groups in spyware campaigns targeting high-risk individuals, including journalists, opposition politicians, and dissidents.

    Wiz

    Google fixed the zero-day flaw with the release of 142.0.7444.175/.176 for Windows, 142.0.7444.176 for Mac, and 142.0.7444.175 for Linux.

    While these new versions are scheduled to roll out to all users in the Stable Desktop channel over the coming weeks, the patch was immediately available when BleepingComputer checked for the latest updates.

    Although the Chrome web browser updates automatically when security patches are available, users can also confirm they’re running the latest version by going to Chrome menu > Help > About Google Chrome, letting the update finish, and then clicking on the ‘Relaunch’ button to install it.

    Google Chrome 142.0.7444.176

    ​​​Although Google has already confirmed that CVE-2025-13223 was used in attacks, it still has to share additional details regarding active exploitation.

    “Access to bug details and links may be kept restricted until a majority of users are updated with a fix,” Google said. “We will also retain restrictions if the bug exists in a third party library that other projects similarly depend on, but haven’t yet fixed.”

    This is the seventh Chrome zero-day exploited in attacks that was fixed by Google this year, with six more patched in March, May, June, July, and September.

    In September and July, it addressed two actively exploited zero-day (CVE-2025-10585 and CVE-2025-6558) reported by Google TAG researchers.

    Google released additional emergency security updates in May to address a Chrome zero-day vulnerability (CVE-2025-4664) that enabled threat actors to hijack accounts. The updates also fixed an out-of-bounds read and a write flaw (CVE-2025-5419) in the V8 JavaScript engine discovered by Google TAG in June.

    In March, Google also patched a high-severity sandbox escape flaw (CVE-2025-2783) reported by Kaspersky, which was exploited in espionage attacks against Russian media outlets and government organizations.

    In 2024, Google addressed 10 more zero-day bugs that were demoed during Pwn2Own hacking competitions or exploited in attacks.


    Wiz

    As MCP (Model Context Protocol) becomes the standard for connecting LLMs to tools and data, security teams are moving fast to keep these new services safe.

    This free cheat sheet outlines 7 best practices you can start using today.



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

    Related Posts

    Apple fixes two zero-day flaws exploited in ‘sophisticated’ attacks

    December 14, 2025

    Apple Issues Security Updates After Two WebKit Flaws Found Exploited in the Wild

    December 13, 2025

    Microsoft Patch Tuesday, December 2025 Edition – Krebs on Security

    December 12, 2025

    How to harness today’s diverse analyst and tester landscape to paint a security masterpiece

    December 11, 2025

    Brushing Scams: What They Are and How to Stay Safe From Unsolicited Packages

    December 10, 2025

    The Real Magic of the Season: AI-Powered Workplaces

    December 9, 2025
    Top Posts

    Understanding U-Net Architecture in Deep Learning

    November 25, 20257 Views

    Microsoft 365 Copilot now enables you to build apps and workflows

    October 29, 20257 Views

    Here’s the latest company planning for gene-edited babies

    November 2, 20256 Views
    Don't Miss

    OpenAI launches GPT-5.2 as it battles Google’s Gemini 3 for AI model supremacy – Computerworld

    December 14, 2025

    Rachid ‘Rush’ Wehbi, CEO of e-commerce platform Sell The Trend, has tested GPT-5.2 under real-world…

    The Download: Expanded carrier screening, and how Southeast Asia plans to get to space

    December 14, 2025

    How Bayer transforms Pharma R&D with a cloud-based data science ecosystem using Amazon SageMaker

    December 14, 2025

    How cloud infrastructure shapes the modern Diablo experience 

    December 14, 2025
    Stay In Touch
    • Facebook
    • Instagram
    About Us

    At GeekFence, we are a team of tech-enthusiasts, industry watchers and content creators who believe that technology isn’t just about gadgets—it’s about how innovation transforms our lives, work and society. We’ve come together to build a place where readers, thinkers and industry insiders can converge to explore what’s next in tech.

    Our Picks

    OpenAI launches GPT-5.2 as it battles Google’s Gemini 3 for AI model supremacy – Computerworld

    December 14, 2025

    The Download: Expanded carrier screening, and how Southeast Asia plans to get to space

    December 14, 2025

    Subscribe to Updates

    Please enable JavaScript in your browser to complete this form.
    Loading
    • About Us
    • Contact Us
    • Disclaimer
    • Privacy Policy
    • Terms and Conditions
    © 2025 Geekfence.All Rigt Reserved.

    Type above and press Enter to search. Press Esc to cancel.