ZeroHour
Help Net Securitypublished ()ingested @zeljkazorz

Google patches actively exploited Chrome zero-day (CVE‑2025‑6554)

criticalExploit / PoC exploited in the wildimportance 60CVE-2025-6554

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2025-6554
Type Confusion in Google Chrome V8 Allows Arbitrary Read/Write (Actively Exploited)

CVE-2025-6554 is a type confusion vulnerability (CWE-843) in the V8 JavaScript engine of Google Chrome, affecting versions prior to 138.0.7204.96. A remote attacker can trigger it by inducing a user to open a crafted HTML page, and the flaw permits arbitrary read and write within the browser renderer process. Successful exploitation yields high confidentiality and integrity impact, and V8 type confusion bugs are commonly used as the first stage toward a full browser compromise. Any user of an unpatched Chrome or Chromium-based browser is exposed, and the flaw is being actively exploited in the wild as a zero-day; CISA added it to the Known Exploited Vulnerabilities catalog on 2025-07-02. Ransomware usage is not confirmed (reported as unknown), and no public proof-of-concept is known.

Do: Update Chrome to 138.0.7204.96 or later (check chrome://settings/help) and restart the browser to load the patched V8; users of Chromium-derived browsers (Edge, Brave, Opera, etc.) should install their vendor's corresponding V8 patch. Organizations must apply vendor mitigations or follow BOD 22-01 guidance given the KEV listing, and should inventory managed browsers and force-update policies to confirm rollout.

8.113% KEV
  • Google Chrome all versions prior to 138.0.7204.96
  • Google Chromium V8 JavaScript engine V8 versions shipping in Chromium/Chrome prior to the 138.0.7204.96 fix
mass≈3+ billion Chrome users; effectively every desktop Chrome installation running a build older than 138.0.7204.96
Full article303 words · extracted from helpnetsecurity.com · click to collapse

Google has released a security update for Chrome to address a zero‑day vulnerability (CVE-2025-6554) that its Threat Analysis Group (TAG) discovered and reported last week.

“Google is aware that an exploit for CVE-2025-6554 exists in the wild,” the company said.

About CVE-2025-6554

CVE-2025-6554 is a type confusion vulnerability in V8, the JavaScript and WebAssembly engine at the heart of Chrome and Chromium-based browsers.

Remote, unauthenticated attackers can exploit this flaw by serving crafted HTML pages to targets. The pages may trigger the flaw and allow them to execute arbitrary read/write operations. In some cases, this could lead to full remote code execution.

As per usual, Google has withheld exploit details pending broad deployment of the fix. But given that the vulnerability was discovered by Clément Lecigne of Google’s TAG, it’s likely that it is being leveraged in extremely targeted and likely state-sponsored attacks.

For example, a zero-day V8 flaw patched in August 2024 has been leveraged by a North Korean threat actor to target organizations in the cryptocurrency sector.

Update quickly

The vulnerability was reported by the researchers on June 25, 2025. The day after, Google pushed out a configuration change to the Chrome Stable channel across all platforms, as a temporary mitigation.

CVE-2025-6554 has now been fixed in:

  • Chrome v138.0.7204.96/.97 for Windows
  • Chrome v138.0.7204.92/.93 for Mac
  • Chrome v138.0.7204.96 for Linux

Because the flaw is being actively exploited in the wild, users are urged to update quickly.

Depending on your operating system and whether Chrome auto-updating is enabled, you can either apply the update manually or simply restart the browser to implement the fix.

Security updates for Chromium-based browsers like Microsoft Edge, Brave, Opera, and Vivaldi are still in the works.

Subscribe to our breaking news e-mail alert to never miss out on the latest breaches, vulnerabilities and cybersecurity threats. Subscribe here!

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2025/07/01/google-patches-actively-exploited-chrome-cve-2025-6554/