Google has just released an emergency security update that affects millions of Chrome users. This is a type confusion vulnerability in JavaScript and WebAssembly V8 processors that can be exploited to execute malicious code or cause the browser to crash.

According to information from Google, the CVE-2025-10585 vulnerability was discovered and reported by the Threat Analysis Group (TAG) on September 16, 2025. However, Google did not disclose details about the attack method, the identity of the hacker group or the scale of the impact, for the reason of ensuring user safety before the patch is widely updated.
Since the beginning of 2025, 6 Zero-Day vulnerabilities in Chrome have been discovered and fixed.
This is the sixth zero-day vulnerability in Chrome to be exploited or have been released as a proof-of-concept (PoC) this year. The previous vulnerabilities include: CVE-2025-2783, CVE-2025-4664, CVE-2025-5419, CVE-2025-6554 and CVE-2025-6558.

To be safe, it is recommended to update the browser to version 140.0.7339.185/.186 (or higher) on Windows and macOS by typing the command line chrome://settings/help in the address bar and wait a moment for the download to complete, then press Relaunch to restart.
Users of Chromium-based browsers such as Microsoft Edge, Brave, Opera, Vivaldi, Dia… are also advised to update as soon as the patch is available.
There is currently no information on the extent of damage or specific targets of attacks related to this vulnerability.
Source: https://khoahocdoisong.vn/google-chrome-phat-hanh-ban-va-khan-cap-nguoi-dung-can-cap-nhat-ngay-post2149056027.html
Comment (0)