Google Issues Security Fix for Actively Exploited Chrome V8 Zero-Day Vulnerability - The Hacker News
The Hacker NewsArchived Mar 16, 2026✓ Full text saved
Google Issues Security Fix for Actively Exploited Chrome V8 Zero-Day Vulnerability The Hacker News
Full text archived locally
✦ AI Summary· Claude Sonnet
Google Issues Security Fix for Actively Exploited Chrome V8 Zero-Day Vulnerability
Ravie LakshmananNov 18, 2025Browser Security / Vulnerability
Google on Monday released security updates for its Chrome browser to address two security flaws, including one that has come under active exploitation in the wild.
The vulnerability in question is CVE-2025-13223 (CVSS score: 8.8), a type confusion vulnerability in the V8 JavaScript and WebAssembly engine that could be exploited to achieve arbitrary code execution or program crashes.
"Type Confusion in V8 in Google Chrome prior to 142.0.7444.175 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page," according to a description of the flaw in the NIST National Vulnerability Database (NVD).
Clément Lecigne of Google's Threat Analysis Group (TAG) has been credited with discovering and reporting the flaw on November 12, 2025. Google has not shared any details on who is behind the attacks, who may have been targeted, or the scale of such efforts.
However, the tech giant acknowledged that an "exploit for CVE-2025-13223 exists in the wild."
With the latest update, Google has addressed seven zero-day flaws in Chrome that have been either actively exploited or demonstrated as a proof-of-concept (PoC) since the start of the year. The list includes CVE-2025-2783, CVE-2025-4664, CVE-2025-5419, CVE-2025-6554, CVE-2025-6558, and CVE-2025-10585.
CVE-2025-13223 is also the third actively exploited type confusion bug discovered in V8 this year after CVE-2025-6554 and CVE-2025-10585.
Also patched by Google as part of this patch is another type confusion vulnerability in V8 (CVE-2025-13224, CVSS score: 8.8) that was flagged by its artificial intelligence (AI) agent Big Sleep.
To safeguard against potential threats, it's advised to update their Chrome browser to versions 142.0.7444.175/.176 for Windows, 142.0.7444.176 for Apple macOS, and 142.0.7444.175 for Linux. To make sure the latest updates are installed, users can navigate to More > Help > About Google Chrome and select Relaunch.
Users of other Chromium-based browsers, such as Microsoft Edge, Brave, Opera, and Vivaldi, are also advised to apply the fixes as and when they become available.
Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.
SHARE
Tweet
Share
Share
SHARE
browser security, Chrome, cybersecurity, Google, JavaScript, Vulnerability, zero-day
Trending News
Google Confirms CVE-2026-21385 in Qualcomm Android Component Exploited
APT28 Tied to CVE-2026-21513 MSHTML 0-Day Exploited Before Feb 2026 Patch Tuesday
⚡ Weekly Recap: Qualcomm 0-Day, iOS Exploit Chains, AirSnitch Attack and Vibe-Coded Malware
Cisco Confirms Active Exploitation of Two Catalyst SD-WAN Manager Vulnerabilities
Microsoft Reveals ClickFix Campaign Using Windows Terminal to Deploy Lumma Stealer
OpenAI Codex Security Scanned 1.2 Million Commits and Found 10,561 High-Severity Issues
New Chrome Vulnerability Let Malicious Extensions Escalate Privileges via Gemini Panel
Open-Source CyberStrikeAI Deployed in AI-Driven FortiGate Attacks Across 55 Countries
Starkiller Phishing Suite Uses AitM Reverse Proxy to Bypass Multi-Factor Authentication
Anthropic Finds 22 Firefox Vulnerabilities Using Claude Opus 4.6 AI Model
Coruna iOS Exploit Kit Uses 23 Exploits Across Five Chains Targeting iOS 13–17.2.1
ClawJacked Flaw Lets Malicious Sites Hijack Local OpenClaw AI Agents via WebSocket
149 Hacktivist DDoS Attacks Hit 110 Organizations in 16 Countries After Middle East Conflict
ThreatsDay Bulletin: DDR5 Bot Scalping, Samsung TV Tracking, Reddit Privacy Fine and More
Load More ▼
Popular Resources
19,053 Confirmed Breaches in 2025 – Key Trends and Predictions for 2026
Identity Controls Checklist: Find Missing Protections in Apps
Read CYBER360 2026: From Zero Trust Limits to Data-Centric Security Paths
Self-Hosted WAF: Block SQLi, XSS, and Bots Before They Reach Your Apps