• News/
  • https://www.theregister.com/2025/09/18/google_emergency_patch_chrome_0_day/

Google pushes emergency patch for Chrome 0-day – check your browser version now

The Register
·
Jessica Lyons
·
Published Sep 18, 2025
·
Updated

Google pushed an emergency patch for a high-severity Chrome flaw, already under active exploitation. So it's time to make sure you're running the most recent version of the web browser. The vuln, tracked as CVE-2025-10585, is a type confusion flaw in the V8 JavaScript and WebAssembly engine. This kind of vulnerability exists when the engine misinterprets a block of memory as one type of object when it's actually something else, and can lead to system crashes, arbitrary code execution, and when chained with other bugs, potentially a full system compromise via a malicious HTML page. "Google is aware that an exploit for CVE-2025-10585 exists in the wild," the Chocolate Factory warned. While you're patching… WatchGuard released an update to fix a critical remote code execution bug tracked as CVE-2025-9242 in its Firebox firewalls. It's due to an out-of-bounds write flaw and "affects both the mobile user VPN with IKEv2 and the branch office VPN using IKEv2 when configured with a dynamic gateway peer,"  the vendor warned in a Wednesday advisory. CVE-2025-9242 affects Fireware OS 11.10.2 up to and including 11.12.4_Update1, 12.0 up to and including 12.11.3 and 2025.1. It's fixed in versions 12.3.1_Update3 (B722811), 12.5.13, 12.11.4, and 2025.1.1. Google Threat Analysis Group (TAG) discovered and reported the vulnerability, and, as usual with Google security holes, there's no additional information about who is abusing this vulnerability and what they are doing with the illicit acce...

Read full article

Affected Software

2 affected components
Google Chrome
WatchGuard Firebox
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses Google's release of an emergency patch for a critical 0-day vulnerability in Chrome.

2

What specific vulnerability is addressed in the article?

The vulnerability is tracked as CVE-2025-1058 and is described as high-severity and under active exploitation.

3

What should users do to protect themselves according to the article?

Users are advised to check and ensure they are running the most recent version of Google Chrome.

4

What software products are affected by this security issue?

The primary affected software is Google Chrome, and potentially the WatchGuard Firebox.

5

How severe is the vulnerability mentioned in the article?

The vulnerability is classified as high-severity, indicating it poses a significant security risk.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203