Critical Chrome Zero-Day Under Active Attack: Millions at Risk from V8 Engine Exploit

# Google Patches Critical Chrome Zero-Day Vulnerability Under Active Attack

Google has released emergency security updates for its Chrome browser to fix four vulnerabilities, including a dangerous zero-day flaw that cybercriminals are actively exploiting in real-world attacks.

## The Critical Vulnerability

The most serious threat is **CVE-2025-10585**, a type confusion vulnerability found in Chrome’s V8 JavaScript engine. This flaw allows attackers to manipulate how the browser processes code, potentially leading to:

– Arbitrary code execution on victims’ computers
– Complete system compromise
– Browser crashes and data theft

Google’s internal security team discovered this vulnerability on September 16, 2025, but the company has kept details limited to prevent other hackers from exploiting it before users can update their browsers.

## Growing Chrome Security Concerns

This marks the **sixth zero-day vulnerability** in Chrome this year that has been either actively exploited or demonstrated by security researchers. The previous five include CVE-2025-2783, CVE-2025-4664, CVE-2025-5419, CVE-2025-6554, and CVE-2025-6558.

## Immediate Action Required

Users must update Chrome immediately to protect themselves:

**Update Instructions:**
1. Open Chrome browser
2. Click the three-dot menu (More)
3. Go to Help > About Google Chrome
4. Allow automatic updates to install
5. Click “Relaunch” when prompted

**Target Versions:**
– Windows/macOS: Version 140.0.7339.185 or .186
– Linux: Version 140.0.7339.185

## Beyond Chrome Users

Users of other Chromium-based browsers should also watch for updates, including:
– Microsoft Edge
– Brave Browser
– Opera
– Vivaldi

These browsers typically release their own security patches within days of Google’s updates.

The active exploitation of this vulnerability makes immediate updating critical for all Chrome users to prevent potential cyberattacks.

Share This Article