• News/
  • https://www.zdnet.com/article/update-chrome-asap-attackers-are-already-exploiting-this-nasty-zero-day-flaw/

Update Chrome ASAP - attackers are already exploiting this nasty zero-day flaw

ZDNet
·
Lance Whitney
·
Published Nov 19, 2025
·
Updated

Follow ZDNET: Add us as a preferred source on Google. Another day, another zero-day, at least for Google Chrome. In an advisory released Monday, Google warned of a dangerous new security vulnerability affecting its popular browser. Fortunately, the latest update squashes the bug. Here are the details. Rated as a high security flaw, the zero day labeled CVE-2025-13223 is described as: "Type Confusion in V8 in Google Chrome prior to 142.0.7444.175 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page." Also: I used this free tool to see what data the internet has on me - and the results were disturbing In plain English, Chrome's V8 JavaScript engine fails to correctly treat a specific type of data, leading to memory corruption. An attacker could exploit that weakness through a web page designed to run malicious code or otherwise wreak havoc with the browser. In its advisory, Google revealed that an exploit for the flaw exists in the wild. That means attackers were aware of the vulnerability and already tried to take advantage of it to prey on potential victims. Zero-day flaws are particularly serious as they represent an open invitation to hackers. They're known as zero days because the vendor doesn't know about them (e.g., knows about them for zero days). As such, no patch exists, allowing attackers to easily exploit them. Also: AI's scary new trick: Conducting cyberattacks instead of just helping out This latest flaw was discovered on Nov. 1...

Read full article

Affected Software

1 affected component
Google Chrome=142.0.7444.175
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses a zero-day vulnerability affecting Google Chrome that is being actively exploited by attackers.

2

What security implications are discussed in the article?

The article highlights the urgency of updating Chrome to mitigate risks associated with the active exploitation of the zero-day flaw.

3

What products or software are affected by the vulnerability?

The vulnerability specifically affects the Google Chrome browser.

4

What is the recommended action for Chrome users?

Users are advised to update their Chrome browser as soon as possible to protect against the exploitation of the vulnerability.

5

When was the security vulnerability announced by Google?

The security vulnerability was announced on November 19, 2025.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203