Google Patches Actively Exploited Chrome Zero-Day Flaw

Google patches three Chrome vulnerabilities including actively exploited ANGLE buffer overflow flaw

  • Google released security updates for Chrome addressing three vulnerabilities, one actively exploited.
  • The main flaw resides in the open-source ANGLE graphics library as a buffer overflow issue.
  • Eight zero-day vulnerabilities have been patched in Chrome since early 2025.
  • Users and Chromium-based browser operators should promptly install the updates.

Google issued security patches on December 11, 2025, for its Chrome browser to fix three vulnerabilities, including one currently exploited in the wild. The actively exploited flaw is tracked as Chromium issue ID “466192044.” Google has withheld specific details about the CVE number, affected components, and the nature of the vulnerability.

- Advertisement -

A GitHub commit linked to the bug report identifies the flaw within the Almost Native Graphics Layer Engine (ANGLE), a library used in Chrome. The problem involves improper buffer sizing in ANGLE’s Metal renderer, likely causing a buffer overflow vulnerability that may lead to memory corruption, crashes, or execution of arbitrary code. The commit message specifies, “Metal: Don’t use pixelsDepthPitch to size buffers. pixelsDepthPitch is based on GL_UNPACK_IMAGE_HEIGHT, which can be smaller than the image height.”

Google acknowledged the existence of exploits targeting this issue and noted that further information is being coordinated. The company did not disclose threat actor identities or affected targets to protect users and prevent exploitation before widespread patch application, as outlined on the official Chrome Releases blog.

Alongside the high-severity ANGLE vulnerability, two medium-severity security issues were addressed: CVE-2025-14372, a use-after-free flaw in the Password Manager, and CVE-2025-14373, an inappropriate implementation in the Toolbar.

Since early 2025, Google has patched a total of eight zero-day vulnerabilities in Chrome, including CVEs such as CVE-2025-2783, CVE-2025-4664, and CVE-2025-13223. Users are advised to update their Chrome versions to 143.0.7499.109 or higher on Windows, macOS, and Linux to mitigate risks. To verify installation, users can navigate to More > Help > About Google Chrome and relaunch the browser.

- Advertisement -

Users of other Chromium-based browsers like Microsoft Edge, Brave, Opera, and Vivaldi should also apply corresponding updates as they become available to maintain security.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -

Latest News

Ethereum Leads Bitcoin Liquidations as Macro Headwinds Bite.

Ethereum led crypto liquidations over the last 24 hours, surpassing Bitcoin.Total crypto liquidations totaled...

Bitcoin Falls Amid US-EU Tariff Fears, Drops Near $92K today

Bitcoin traded near $92,000 on Jan. 19 after a weekend decline tied to concerns...

UK committee: regulators lag as AI reshapes financial sector

The UK’s Treasury Committee warns AI use in finance is outpacing regulatory oversight.Regulators are...

Bitcoin Holds at $92K Amid Trade Tensions, Volatility Fears.

Bitcoin stabilized near $92,000 after a liquidation-driven sell-off on Monday.Options markets show rising demand...

Trove Keeps $9.4M for Solana Pivot; Investors Demand Refunds

Trove Markets will keep about $9.4 million of an over $11.5 million raise and...
- Advertisement -

Must Read

What Is a Sim Swap Hack?

You've likely heard the term 'sim-swap,' but do you really know what it means? It's a type of fraud that's rapidly increasing, where scammers...
Bitcoin (BTC) $ 91,441.00 1.07%
Ethereum (ETH) $ 3,163.70 0.93%
XRP (XRP) $ 1.96 0.04%
Bittensor (TAO) $ 246.65 1.05%
Polkadot (DOT) $ 2.02 2.10%
Cardano (ADA) $ 0.367118 0.86%
Chainlink (LINK) $ 12.77 0.00%
Hyperliquid (HYPE) $ 23.32 2.11%
Monero (XMR) $ 617.98 0.33%
Hedera (HBAR) $ 0.110073 0.60%
Toncoin (TON) $ 1.56 2.25%