Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Google Researchers Find New Chrome Zero-Day

Google Researchers Find New Chrome Zero-Day

Posted on June 3, 2025June 3, 2025 By CWS

Google on Monday launched a recent Chrome 137 replace to deal with three vulnerabilities, together with a high-severity bug exploited within the wild.

Tracked as CVE-2025-5419, the zero-day is described as an out-of-bounds learn and write situation within the V8 JavaScript engine.

“Google is conscious that an exploit for CVE-2025-5419 exists within the wild,” the web big’s advisory reads. No additional particulars on the safety defect or the exploit have been supplied.

Nonetheless, the corporate credited Clement Lecigne and Benoît Sevens of Google Risk Evaluation Group (TAG) for reporting the difficulty.

TAG researchers beforehand reported a number of vulnerabilities exploited by business surveillance software program distributors, together with such bugs in Chrome. Flaws in Google’s browser are sometimes exploited by spyware and adware distributors and CVE-2025-5419 could possibly be no completely different.

In response to a NIST advisory, the exploited zero-day “allowed a distant attacker to doubtlessly exploit heap corruption through a crafted HTML web page”. It needs to be famous that the exploitation of out-of-bounds defects usually results in arbitrary code execution.

The newest browser replace additionally addresses CVE-2025-5068, a medium-severity use-after-free in Blink that earned the reporting researcher a $1,000 bug bounty. No reward will probably be handed out for the zero-day.

The newest Chrome iteration is now rolling out as model 137.0.7151.68/.69 for Home windows and macOS, and as model 137.0.7151.68 for Linux.Commercial. Scroll to proceed studying.

The patch for CVE-2025-5419 comes after a Chrome sandbox escape (CVE-2025-2783) exploited by a Russian state-sponsored group was caught and patched in March. Firefox too was patched in opposition to an analogous vulnerability.

In mid-Might, Google launched a Chrome 136 replace and warned that an exploit for one of many addressed bugs existed within the wild. The patch got here roughly one week after a safety researcher had launched info on the flaw on X.

Associated: Chrome 137, Firefox 139 Patch Excessive-Severity Vulnerabilities

Associated: Chrome to Mistrust Chunghwa Telecom and Netlock Certificates

Associated: Chrome 136 Replace Patches Vulnerability With ‘Exploit within the Wild’

Associated: Google Tracked 75 Zero-Days in 2024

Security Week News Tags:Chrome, Find, Google, Researchers, ZeroDay

Post navigation

Previous Post: Microsoft, CrowdStrike Lead Effort to Map Threat Actor Names
Next Post: Android Trojan Crocodilus Now Active in 8 Countries, Targeting Banks and Crypto Wallets

Related Posts

Poland Sees Spike in Cyberattacks Targeting Energy Sector Poland Sees Spike in Cyberattacks Targeting Energy Sector Security Week News
Industry Reactions to Trump Cybersecurity Executive Order: Feedback Friday Industry Reactions to Trump Cybersecurity Executive Order: Feedback Friday Security Week News
New BootROM Exploit Threatens iPhone Security New BootROM Exploit Threatens iPhone Security Security Week News
MokN Raises  Million for Phish-Back Solution MokN Raises $3 Million for Phish-Back Solution Security Week News
Android Update Fixes Critical Remote Code Threat Android Update Fixes Critical Remote Code Threat Security Week News
Critical WP Maps Pro Flaw Endangers WordPress Sites Critical WP Maps Pro Flaw Endangers WordPress Sites Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Over 543,000 GitHub Credentials Remain Vulnerable
  • US Treasury Targets ATM Malware Network in Sanctions
  • MikroTik RouterOS Vulnerability Exposes Critical Risks
  • Over 500,000 Active Credentials Found on GitHub
  • Urgent Fixes Issued for Cisco SD-WAN Critical Flaw

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • October 2026
  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Over 543,000 GitHub Credentials Remain Vulnerable
  • US Treasury Targets ATM Malware Network in Sanctions
  • MikroTik RouterOS Vulnerability Exposes Critical Risks
  • Over 500,000 Active Credentials Found on GitHub
  • Urgent Fixes Issued for Cisco SD-WAN Critical Flaw

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark