logo

Chrome zero-day under active attack: visiting the wrong site could hijack your browser

ID: 088d3274-8ab7-5f81-af29-00cf27665625

STIX ID: report--088d3274-8ab7-5f81-af29-00cf27665625

Feed Name: Malwarebytes Blog

Threat Score
85/100

Date Published: 2025-11-18

Date Updated: 2026-04-28

...
...

**Google released Chrome version 142.0.7444.175/.176 (Windows), 142.0.7444.176 (macOS), and 142.0.7444.175 (Linux) to patch two high‑severity type‑confusion vulnerabilities in the V8 JavaScript engine (CVE-2025-13223 and CVE-2025-13224), one of which (CVE-2025-13223) is reported to be exploited in the wild and can enable heap corruption and remote code execution simply by visiting a malicious page — users and administrators should apply the update and restart browsers immediately.**

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.