• News/
  • https://www.bleepingcomputer.com/news/security/google-patches-sixth-chrome-zero-day-exploited-in-attacks-this-year/

Google patches sixth Chrome zero-day exploited in attacks this year

BleepingComputer
·
Sergiu Gatlan
·
Published Sep 18, 2025
·
Updated

Google has released emergency security updates to patch a Chrome zero-day vulnerability, the sixth one tagged as exploited in attacks since the start of the year. While it didn't specifically say whether this security flaw is still being actively abused in the wild, the company warned that it has a public exploit, a common indicator of active exploitation. "Google is aware that an exploit for CVE-2025-10585 exists in the wild," Google warned in a security advisory published on Wednesday. This high-severity zero-day vulnerability is caused by a type confusion weakness in the web browser's V8 JavaScript engine, reported by Google's Threat Analysis Group on Tuesday. Google TAG frequently flags zero-days exploited by government-sponsored threat actors in targeted spyware campaigns targeting high-risk individuals, including but not limited to opposition politicians, dissidents, and journalists. The company mitigated the security issue one day later with the release of 140.0.7339.185/.186 for Windows/Mac, and 140.0.7339.185 for Linux, versions that will roll out to the Stable Desktop channel over the coming weeks. While Chrome automatically updates when new security patches are available, you can speed up the process by going to the Chrome menu > Help > About Google Chrome, allowing the update to finish, and then clicking the 'Relaunch' button to install it immediately.

​​Although Google has already confirmed that CVE-2025-10585 was used in attacks, it still has to share addition...

Read full article

Affected Software

2 affected components
Google Chrome=140.0.7339.185
Google Chrome=140.0.7339.186
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses Google releasing emergency security updates to patch a sixth zero-day vulnerability in Chrome that has been exploited this year.

2

What security implications are discussed in the article?

The article highlights the risk posed by a zero-day vulnerability in Chrome that hackers are actively exploiting.

3

What versions of Chrome are affected by this vulnerability?

The affected versions of Chrome are 140.0.7339.185 and 140.0.7339.186.

4

How many zero-day vulnerabilities in Chrome have been reported this year?

The article notes that this is the sixth zero-day vulnerability reported in Chrome for the year.

5

What should users do in response to this vulnerability?

Users are advised to update their Chrome browser immediately to the latest version to protect against this vulnerability.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203