• News/
  • https://www.bleepingcomputer.com/news/security/google-fixes-fourth-actively-exploited-chrome-zero-day-of-2025/

Google fixes fourth actively exploited Chrome zero-day of 2025

BleepingComputer
·
Sergiu Gatlan
·
Published Jul 1, 2025
·
Updated

Google has released emergency updates to patch another Chrome zero-day vulnerability exploited in attacks, marking the fourth such flaw fixed since the start of the year. "Google is aware that an exploit for CVE-2025-6554 exists in the wild," the browser vendor said in a security advisoryissued on Monday. "This issue was mitigated on 2025-06-26 by a configuration change pushed out to Stable channel across all platforms." The company fixed the zero-day for users in the Stable Desktop channel, with new versions rolling out worldwide to Windows (138.0.7204.96/.97), Mac (138.0.7204.92/.93), and Linux users (138.0.7204.96) one day after the issue was reported to Google. ​​​The bug was discovered by Clément Lecigne of Google's Threat Analysis Group (TAG), a collective of security researchers focused on defending Google customers from state-sponsored and other similar attacks. Google TAG frequently discovers zero-day exploits deployed by government-sponsored threat actors in targeted attacks to infect high-risk individuals, including opposition politicians, dissidents, and journalists, with spyware. Although the security updates patching CVE-2025-6554 could take days or weeks to reach all users, according to Google, they were immediately available when BleepingComputer checked for updates earlier today. Users who prefer not to update manually can also rely on their web browser to automatically check for new updates and install them after the next launch.

The zero-day bug fixed tod...

Read full article

Affected Software

4 affected components
Google Chrome=138.0.7204.96
Google Chrome=138.0.7204.97
Google Chrome=138.0.7204.92
Google Chrome=138.0.7204.93
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses the emergency updates released by Google to fix a Chrome zero-day vulnerability that is currently being exploited.

2

What is the specific vulnerability addressed in the updates?

The vulnerability addressed is identified as CVE-2025-6554, which has been actively exploited in attacks.

3

How many zero-day vulnerabilities has Google fixed in Chrome this year?

Google has fixed four actively exploited zero-day vulnerabilities in Chrome since the beginning of 2025.

4

Which versions of Google Chrome are affected by this zero-day vulnerability?

The versions affected by this vulnerability include Google Chrome 138.0.7204.92, 138.0.7204.93, 138.0.7204.96, and 138.0.7204.97.

5

What should users do in response to this vulnerability?

Users should update their Google Chrome browser to the latest version to protect against this vulnerability and any potential exploits.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203