Google has urgently updated its Chrome browser following the discovery of a zero-day vulnerability affecting its V8 engine, which could potentially expose 3 billion users to security risks. This flaw, identified as CVE-2025-5419, allows hackers to manipulate device memory and access sensitive data without authorization. Although classified as “high severity,” the active exploitation of this vulnerability heightens its threat level. Google’s Threat Analysis Group detected the issue on May 27, 2025, and promptly addressed it with a server-side configuration change the following day. The company has since released Chrome version 137.0.7151.68 for Windows and Linux, and 137.0.7151.69 for Mac to resolve the issue. In response, US cybersecurity authorities have mandated that federal agencies install the update within 21 days, as per CISA guidelines.
previous post