• News/
  • https://www.theregister.com/2025/11/18/google_chrome_seventh_0_day/

Google Chrome bug exploited as an 0-day - patch now or risk full system compromise

The Register
·
Jessica Lyons
·
Published Nov 18, 2025
·
Updated

Google pushed an emergency patch on Monday for a high-severity Chrome bug that attackers have already found and exploited in the wild. The vulnerability, tracked as CVE-2025-13223, is a type confusion flaw in the V8 JavaScript engine, and it's the seventh Chrome zero-day this year. All have since been patched. But if you use Chrome as your web browser, make sure you are running the most recent version - or risk full system compromise. This type of vulnerability happens when the engine misinterprets a block of memory as one type of object and treats it as something it's not. This can lead to system crashes and arbitrary code execution, and if it's chained with other bugs can potentially lead to a full system compromise via a crafted HTML page. "Google is aware that an exploit for CVE-2025-13223 exists in the wild," the Monday security alert warned. Also on Monday, Google issued a second emergency patch for another high-severity type confusion bug in Chrome's V8 engine. This one is tracked as CVE-2025-13224. As of now, there's no reports of exploitation - so that's another reason to update sooner than later. Google's LLM-based bug hunting tool Big Sleep found CVE-2025-13224 in October, and a human - the Chocolate Factory's own Clément Lecigne - discovered CVE-2025-13223 on November 12. Lecigne is a spyware hunter with Google's Threat Analysis Group (TAG) credited with finding and disclosing several of these types of Chrome zero-days. While we don't have any details about who is...

Read full article

Affected Software

1 affected component
Google Chrome
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main focus of this article?

The article discusses a newly discovered zero-day vulnerability in Google Chrome that is actively being exploited.

2

What vulnerability is highlighted in the article?

The vulnerability is a type confusion flaw in the V8 JavaScript engine, tracked as CVE-2025-13223.

3

What action is recommended for users of Google Chrome?

Users are advised to apply the emergency patch released by Google to protect their systems.

4

How many zero-day vulnerabilities has Google Chrome had this year?

This is the seventh zero-day vulnerability reported for Google Chrome in 2025.

5

What could happen if users do not patch their Chrome browser?

Failure to patch could lead to full system compromise due to the exploited vulnerability.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203