Chrome Users Under Attack: Google Rushes Emergency Fix for Sixth Zero-Day Exploit This Year

# Google Patches Sixth Chrome Zero-Day Vulnerability of 2025

Google has issued emergency security updates to address a critical zero-day vulnerability in Chrome, marking the sixth such exploit discovered this year. The company confirmed that attackers are actively using this security flaw in real-world attacks.

## The Vulnerability Details

The high-severity vulnerability, designated CVE-2025-10585, stems from a type confusion weakness in Chrome’s V8 JavaScript engine. Google’s Threat Analysis Group (TAG) reported the flaw on Tuesday, and the company released a fix just one day later.

“Google is aware that an exploit for CVE-2025-10585 exists in the wild,” the company stated in its security advisory. This warning typically indicates that cybercriminals are actively exploiting the vulnerability to target users.

## Who’s at Risk

Google TAG frequently identifies zero-day exploits used by government-sponsored hackers in targeted spyware campaigns. These attacks typically focus on high-risk individuals, including:
– Opposition politicians
– Dissidents
– Journalists
– Other sensitive targets

## Immediate Action Required

Google has released Chrome versions 140.0.7339.185/.186 for Windows and Mac, and 140.0.7339.185 for Linux. While Chrome updates automatically, users can expedite the process by:

1. Opening Chrome menu
2. Navigating to Help > About Google Chrome
3. Allowing the update to complete
4. Clicking ‘Relaunch’ to install immediately

## Limited Information Available

Google is withholding specific details about how the vulnerability is being exploited. The company explained that “access to bug details and links may be kept restricted until a majority of users are updated with a fix.”

## Growing Trend of Chrome Exploits

This latest patch continues a concerning trend for 2025. Google has now fixed six actively exploited Chrome zero-days this year, with previous vulnerabilities addressed in March, May, June, and July. Notable examples include:

– **July**: CVE-2025-6558 – Allowed attackers to escape browser sandbox protection
– **June**: CVE-2025-5419 – Out-of-bounds read/write weakness in V8 engine
– **May**: CVE-2025-4664 – Enabled account hijacking
– **March**: CVE-2025-2783 – Sandbox escape used in espionage attacks against Russian organizations

In 2024, Google patched 10 additional zero-day vulnerabilities that were either demonstrated at security conferences or exploited in attacks.

## The Bottom Line

Chrome users should update their browsers immediately to protect against this actively exploited vulnerability. The increasing frequency of zero-day discoveries highlights the ongoing cat-and-mouse game between security researchers and cybercriminals, making prompt updates more critical than ever.

Share This Article