Chrome typically updates automatically, but users can manually check for updates by navigating to Chrome’s settings menu and selecting “About Google Chrome.” Given the active exploitation of CVE-2025-6558, delaying this update could expose users to significant security risks. Google has released an emergency security update for Chrome, addressing a critical zero-day vulnerability that attackers are actively exploiting in real-world attacks. Users must update Chrome immediately as the active exploitation poses immediate security risks to unpatched systems. The update incorporates fixes from Google’s ongoing internal security initiatives, including results from AddressSanitizer, MemorySanitizer, UndefinedBehaviorSanitizer, Control Flow Integrity, libFuzzer, and AFL testing frameworks. Chrome versions 138.0.7204.157/.158 (Windows/Mac) and 138.0.7204.157 (Linux) fix six security vulnerabilities, including three high-severity flaws. The update addresses six security vulnerabilities, with the most severe being the actively exploited zero-day flaw. The researchers’ affiliation with Google’s internal security team suggests the vulnerability may have been identified through advanced threat monitoring or incident response activities. Google emphasized that access to detailed bug information remains restricted until most users receive the security update.
This Cyber News was published on cybersecuritynews.com. Publication date: Wed, 16 Jul 2025 02:55:09 +0000