Source: The Hacker News
Author: info@thehackernews.com (The Hacker News)
URL: https://thehackernews.com/2025/12/chrome-targeted-by-active-in-wild.html
ONE SENTENCE SUMMARY:
Google released Chrome security updates to fix three critical vulnerabilities, including an actively exploited zero-day, urging immediate user updates.
MAIN POINTS:
- Google addressed three security flaws in Chrome, including an actively exploited high-severity vulnerability.
- Information about the CVE identifier, affected component, and flaw nature remains undisclosed.
- Disclosure delay ensures widespread user updates and hinders reverse engineering for exploits.
- Eight zero-day flaws have been addressed in Chrome since early 2025.
- Additional medium-severity vulnerabilities were fixed, including issues in Password Manager and Toolbar.
- Chrome users should update to versions 143.0.7499.109/.110 for Windows/macOS and 143.0.7499.109 for Linux.
- Update process involves navigating to More > Help > About Google Chrome and selecting Relaunch.
- Other Chromium-based browser users, like Microsoft Edge and Brave, should also apply available updates.
- Detailed threat actor and target information remains withheld for security reasons.
- Users are advised to apply patches promptly to safeguard against potential threats.
TAKEAWAYS:
- Immediate update of Chrome is crucial due to actively exploited vulnerabilities.
- Keeping update details private helps protect against further exploits.
- Regular updates are essential as numerous zero-day flaws have been targeted.
- Other Chromium browsers require similar vigilance and updates.
- User diligence in applying updates significantly enhances security.