Tuesday, September 22, 2026

Google Alerts Users to Actively Exploited Chrome 0-Day Vulnerability

Google has released an emergency security update for Chrome to address a critical zero-day vulnerability actively exploited in the wild.

The vulnerability, tracked as issue 466192044, has been classified as “High” severity and poses an immediate threat to Chrome users worldwide.

The tech giant rolled out the patched version 143.0.7499.109/.110 for Windows and Mac systems, with version 143.0.7499.109 for Linux users.

CVE IDSeverityComponentReporter
CVE-2025-14372MediumPassword ManagerWeipeng Jiang (VRI)
CVE-2025-14373MediumToolbarKhalil Zhani

The update will be distributed gradually over the coming days and weeks, with phases for all users. This measured rollout approach ensures stability while prioritizing security patches across the global user base.

Google confirmed that exploit code for the vulnerability already exists in active circulation, prompting the urgent release.

The company has kept technical details about the flaw restricted until a majority of users receive the security fix, a standard practice that protects users still running older versions.

This vulnerability stands out from routine security updates due to its confirmed exploitation status, making it particularly dangerous for unpatched systems.

The December update includes three security fixes. Beyond the actively exploited zero-day, Google patched two additional vulnerabilities.

CVE-2025-14372, classified as Medium severity, addresses a use-after-free flaw in Chrome’s Password Manager.

This vulnerability was discovered by Weipeng Jiang, a security researcher with VRI, and reported on November 14.

CVE-2025-14373, also Medium severity, fixes an inappropriate implementation issue in the Toolbar component, reported by Khalil Zhani on November 18.

Security researchers who contributed to identifying these vulnerabilities received recognition and rewards from Google’s bug bounty program.

The company awarded $2,000 each for the two identified medium-severity bugs, demonstrating its commitment to incentivizing responsible vulnerability disclosure.

Google emphasizes its layered security detection approach, using advanced tools such as AddressSanitizer, MemorySanitizer, and Control Flow Integrity to catch vulnerabilities before they reach production.

These preventive measures help maintain Chrome’s security throughout development cycles.

Users are strongly advised to update Chrome immediately by visiting Settings > About Chrome, which triggers automatic updates. Delayed patching leaves systems vulnerable to potential exploitation.

Organizations managing multiple Chrome instances should prioritize deploying this security update across their infrastructure to mitigate the risks posed by the actively exploited vulnerability.

Follow us on Google NewsLinkedIn, and X to Get Instant Updates and Set GBH as a Preferred Source in Google.

Divya
Divya
Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.

Hot this week

How To Access Dark Web Anonymously and know its Secretive and Mysterious Activities

What is Deep Web The deep web, invisible web, or...

How to Build and Run a Security Operations Center (SOC Guide) – 2023

Today’s Cyber security operations center (CSOC) should have everything...

Russian Hackers Bypass EDR to Deliver a Weaponized TeamViewer Component

TeamViewer's popularity and remote access capabilities make it an...

Web Server Penetration Testing Checklist – 2026

Web server pentesting is performed under three significant categories: identity,...

ATM Penetration Testing – Advanced Testing Methods to Find The Vulnerabilities

ATM Penetration testing, Hackers have found different approaches to...

Aembit Launches Support for Okta Cross App Access, Extending Enterprise Identity Controls to AI Agents

Silver Spring, Maryland, USA, September 22nd, 2026, CyberNewswire Aembit, the...

Critical Linux KVM Flaw Enables Guest-to-Host Escape on ARM64 Systems

A critical vulnerability in the Linux Kernel-based Virtual Machine...

TASK#STOMP PowerShell Backdoor Steals Business Documents and Executes Remote Commands

A Windows-focused backdoor dubbed TASK#STOMP that uses VBScript, PowerShell,...

Hackers Exploit Veeam Agent Vulnerability to Gain SYSTEM-Level Access on Windows

A newly discovered privilege escalation flaw in Veeam Agent...

Critical MaxKB AI Agent Flaw Lets Prompt Injection Execute System Commands

A critical vulnerability in the MaxKB AI knowledge-base platform...

Related Articles

Recent News