ZeroHour
The Hacker Newspublished ()ingested @TheHackersNews

Chrome Zero-Day CVE-2025-6554 Under Active Attack — Google Issues Security Update

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2025-2783
Sandbox Escape via Mojo Handle Flaw in Google Chrome on Windows (CVE-2025-2783)

CVE-2025-2783 is a high-severity sandbox escape in Google Chrome on Windows, caused by an incorrect handle being provided in unspecified circumstances in Mojo, Chrome's inter-process communication layer. It is triggered remotely through a malicious file and requires user interaction; an attacker who has code running inside Chrome's sandboxed renderer can abuse the handle flaw to break out of the Windows sandbox and gain broader access to the host (CVSS scope change with high impact to confidentiality, integrity, and availability). All Google Chrome versions on Windows prior to 134.0.6998.177 are affected, per the vendor fix referenced by CISA. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2025-03-27, and related reporting links it to active exploitation in the ForumTroll APT's phishing campaign against Russian scholars using fake eLibrary emails; ransomware use is unknown. No public proof-of-concept is known, and EPSS assigns a 9.2% probability of exploitation within 30 days (95th percentile).

Do: Update Google Chrome on Windows to 134.0.6998.177 or later immediately and verify deployed browser versions across endpoints; the flaw is in the CISA KEV catalog, so federal agencies must apply vendor mitigations per BOD 22-01 timelines. Because exploitation is tied to malicious files delivered via phishing (e.g., the ForumTroll fake-eLibrary campaign), prioritize patching for users who open untrusted attachments and links, and hunt for associated phishing emails.

8.39% KEV
  • Google Chrome Windows versions prior to 134.0.6998.177
  • Google Chromium (Mojo IPC component) Windows builds prior to the 134.0.6998.177 fix, as listed by CISA (affected component: Google Chromium Mojo)
massbillions of users (Chrome is the world's dominant browser; the Windows-only subset is still likely well over 1 billion)
CVE-2025-4664
Insufficient policy enforcement in Loader in Google Chrome prior to 136.0.7103.113 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

Insufficient policy enforcement in Loader in Google Chrome prior to 136.0.7103.113 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)

NVD description · AI analysis pending
4.36%
  • google chrome
CVE-2025-5419
Actively Exploited Out-of-Bounds Read/Write in Chromium V8 (Chrome, Edge)

CVE-2025-5419 is an out-of-bounds read and write (CWE-125, CWE-787) in the V8 JavaScript engine used by Google Chromium, rated High with a CVSS 3.1 score of 8.8. A remote attacker can trigger it by persuading a user to open a crafted HTML page (network attack vector, user interaction required, no privileges needed). Successful exploitation can corrupt the V8 heap, potentially giving the attacker code execution in the context of the browser with high impact on confidentiality, integrity, and availability. Anyone running the unpatched V8 engine is affected, including Google Chrome prior to 137.0.7151.68 and Chromium-based browsers such as Microsoft Edge that ship the vulnerable engine. The flaw is confirmed exploited in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on 2025-06-05, though ransomware use is not yet known.

Do: Update Google Chrome to 137.0.7151.68 or later and restart the browser to load the fixed V8 (verify the version at chrome://version); apply the corresponding Chromium 137-based security update for Microsoft Edge and confirm via edge://version. Federal agencies must apply vendor mitigations or follow BOD 22-01 cloud-service guidance per the KEV listing. Since exploitation occurs via attacker-crafted web pages, prompt patching is the primary mitigation, and no public PoC is currently known.

8.88% KEV
  • Google Chrome (V8 JavaScript engine) prior to 137.0.7151.68
  • Google Chromium V8 (component per CISA) V8 as shipped in Chrome prior to 137.0.7151.68
  • Microsoft Edge (Chromium-based) builds incorporating the unpatched V8 engine; fixed version number not stated in source data
masson the order of billions of browser users were exposed pre-patch (Chrome alone ~3B+ users at ~65% global browser share, plus hundreds of millions of Edge users)
CVE-2025-6554
Type Confusion in Google Chrome V8 Allows Arbitrary Read/Write (Actively Exploited)

CVE-2025-6554 is a type confusion vulnerability (CWE-843) in the V8 JavaScript engine of Google Chrome, affecting versions prior to 138.0.7204.96. A remote attacker can trigger it by inducing a user to open a crafted HTML page, and the flaw permits arbitrary read and write within the browser renderer process. Successful exploitation yields high confidentiality and integrity impact, and V8 type confusion bugs are commonly used as the first stage toward a full browser compromise. Any user of an unpatched Chrome or Chromium-based browser is exposed, and the flaw is being actively exploited in the wild as a zero-day; CISA added it to the Known Exploited Vulnerabilities catalog on 2025-07-02. Ransomware usage is not confirmed (reported as unknown), and no public proof-of-concept is known.

Do: Update Chrome to 138.0.7204.96 or later (check chrome://settings/help) and restart the browser to load the patched V8; users of Chromium-derived browsers (Edge, Brave, Opera, etc.) should install their vendor's corresponding V8 patch. Organizations must apply vendor mitigations or follow BOD 22-01 guidance given the KEV listing, and should inventory managed browsers and force-update policies to confirm rollout.

8.113% KEV
  • Google Chrome all versions prior to 138.0.7204.96
  • Google Chromium V8 JavaScript engine V8 versions shipping in Chromium/Chrome prior to the 138.0.7204.96 fix
mass≈3+ billion Chrome users; effectively every desktop Chrome installation running a build older than 138.0.7204.96
Full article465 words · extracted from thehackernews.com · click to collapse

Ravie LakshmananJul 01, 2025Vulnerability / Browser Security

Google has released security updates to address a vulnerability in its Chrome browser for which an exploit exists in the wild.

The zero-day vulnerability, tracked as CVE-2025-6554 (CVSS score: 8.1), has been described as a type confusion flaw in the V8 JavaScript and WebAssembly engine.

"Type confusion in V8 in Google Chrome prior to 138.0.7204.96 allowed a remote attacker to perform arbitrary read/write via a crafted HTML page," according to a description of the bug on the NIST's National Vulnerability Database (NVD).

Type confusion vulnerabilities can have severe consequences as they can be exploited to trigger unexpected software behavior, resulting in the execution of arbitrary code and program crashes.

Zero-day bugs like this are especially risky because attackers often start using them before a fix is available. In real-world attacks, these flaws can let hackers install spyware, launch drive-by downloads, or quietly run harmful code — sometimes just by getting someone to open a malicious website.

Clément Lecigne of Google's Threat Analysis Group (TAG) has been credited with discovering and reporting the flaw on June 25, 2025, signaling that it may have been weaponized in highly targeted attacks — possibly involving nation-state actors or surveillance operations. TAG typically detects and investigates serious threats like government-backed attacks.

The tech giant also noted that the issue was mitigated the next day by means of a configuration change that was pushed out to the Stable channel across all platforms. For everyday users, that means the threat may not be widespread yet, but it's still urgent to patch — especially if you’re in roles handling sensitive or high-value data.

Google has not released any additional details about the vulnerability and who may have exploited it, but acknowledged that "an exploit for CVE-2025-6554 exists in the wild."

CVE-2025-6554 is the fourth zero-day vulnerability in Chrome to be addressed by Google since the start of the year after CVE-2025-2783, CVE-2025-4664, and CVE-2025-5419. However, it bears noting that there is no clarity on whether CVE-2025-4664 has been abused in a malicious context.

To safeguard against potential threats, it's advised to update their Chrome browser to versions 138.0.7204.96/.97 for Windows, 138.0.7204.92/.93 for macOS, and 138.0.7204.96 for Linux.

If you’re unsure whether your browser is up to date, go to Settings > Help > About Google Chrome — it should trigger the latest update automatically. For businesses and IT teams managing multiple endpoints, enabling automatic patch management and monitoring browser version compliance is critical.

Users of other Chromium-based browsers such as Microsoft Edge, Brave, Opera, and Vivaldi are also advised to apply the fixes as and when they become available.

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.

Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2025/07/google-patches-critical-zero-day-flaw.html