• News/
  • https://www.bleepingcomputer.com/news/security/google-fixes-new-chrome-zero-day-flaw-exploited-in-attacks/

Google fixes new Chrome zero-day flaw exploited in attacks

BleepingComputer
·
Sergiu Gatlan
·
Published Nov 18, 2025
·
Updated

Google has released an emergency security update to fix the seventh Chrome zero-day vulnerability exploited in attacks this year. "Google is aware that an exploit for CVE-2025-13223 exists in the wild," the search giant warned in a security advisory published on Monday. This high-severity vulnerability is caused by a type confusion weakness in Chrome's V8 JavaScript engine, reported last week by Clement Lecigne of Google's Threat Analysis Group. Google TAG frequently flags zero-day exploits by government-sponsored threat groups in spyware campaigns targeting high-risk individuals, including journalists, opposition politicians, and dissidents. Google fixed the zero-day flaw with the release of 142.0.7444.175/.176 for Windows, 142.0.7444.176 for Mac, and 142.0.7444.175 for Linux. While these new versions are scheduled to roll out to all users in the Stable Desktop channel over the coming weeks, the patch was immediately available when BleepingComputer checked for the latest updates. Although the Chrome web browser updates automatically when security patches are available, users can also confirm they're running the latest version by going to Chrome menu > Help > About Google Chrome, letting the update finish, and then clicking on the 'Relaunch' button to install it.

​​​Although Google has already confirmed that CVE-2025-13223 was used in attacks, it still has to share additional details regarding active exploitation. "Access to bug details and links may be kept restricted unti...

Read full article

Affected Software

3 affected components
Google Chrome=142.0.7444.175
Google Chrome=142.0.7444.176
Google Chrome
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses a newly discovered zero-day vulnerability in Google Chrome that is being actively exploited.

2

What security implications are discussed?

The article highlights the existence of the exploit in the wild and the potential risk it poses to users of affected versions of Chrome.

3

What specific versions of Chrome are affected by this vulnerability?

The vulnerability affects Google Chrome versions 142.0.7444.175 and 142.0.7444.176.

4

What action has Google taken in response to this vulnerability?

Google has released an emergency security update to address the zero-day flaw.

5

What is the identifier for the vulnerability mentioned in the article?

The vulnerability is identified as CVE-2025-13223.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203