Google has released a security update addressing a zero-day vulnerability in the Chrome browser that is currently being actively exploited in the wild.
The flaw, tracked as CVE-2025-6554, is a type confusion vulnerability in Chrome's V8 JavaScript and WebAssembly engine. This issue could allow a remote attacker to execute arbitrary code by luring users to a specially crafted website. Such vulnerabilities are highly dangerous, particularly when exploited prior to public disclosure, and pose a serious risk to individuals and organizations alike.
Zero-day vulnerabilities are often used in highly targeted attacks before a fix is widely available. This is Chrome’s fourth zero-day this year, highlighting the increasing frequency of browser-based threats.
Google has already pushed a fix to the Stable channel. Users are strongly advised to:
Note: Other Chromium-based browsers (e.g., Microsoft Edge, Brave, Opera, Vivaldi) may also be affected and should be updated accordingly when patches are available.
If you’re concerned that your IT team lacks complete visibility, contact us to learn how our AI-powered exposure management platform can help. Contact us today.