XOOMAR
Generic browser shielded from an active zero-day exploit in a dark cybersecurity scene.
CybersecurityJune 15, 2026· 5 min read· By XOOMAR Insights Team

Chrome Zero-Day Lets Attackers Run Code, Patch Now

Share
Updated on August 16, 2026

Updated May 27, 2025: This article has been refreshed with the correct year and the latest context on Google's patching cadence. The vulnerability details and patching instructions remain critically relevant for user security.

XOOMAR Intelligence

Analyst Take

71/ 100
High
4 sources analyzedMedium confidenceTrend10Freshness98Source Trust85Factual Grounding92Signal Cluster20

Google has patched a Chrome zero-day that attackers were already exploiting, and desktop users on Windows, Mac, and Linux must confirm they are no longer running a vulnerable build.

The vulnerability, tracked as CVE-2025-4761, is a high-severity flaw in Chrome V8 that can allow remote code execution through crafted HTML in vulnerable Chrome versions, according to Google's advisory. The immediate question for users and IT teams remains simple: has Chrome actually relaunched after installing the patch?

Google Ships Emergency Chrome Zero-Day Fix for Actively Exploited V8 Bug

Google’s advisory described the bug as a type confusion issue in V8, Chrome’s JavaScript engine. This class of vulnerability has been frequently exploited in the wild and typically carries a CVSS score of 8.8/10 or higher, placing it in the high-severity category.

The exploit path is critical. A remote attacker can use a crafted HTML page to trigger the flaw and potentially execute arbitrary code in the browser context. Chrome’s sandbox creates a boundary between the browser and the operating system, but a V8 code execution bug under active exploitation is serious enough to warrant immediate patch verification.

“Google is aware that an exploit for CVE-2025-4761 exists in the wild,” Google stated in its advisory.

Google did not publish full technical exploit details when it issued the fix. The company said access to bug details and links may remain restricted until a majority of users have updated. This withholding is a standard practice to prevent copycat attacks while the patch rolls out globally.

XOOMAR analysis: This reflects the persistent emergency-patch tradeoff: prioritize widespread installation of the fix first, then provide technical details later. The pace of Chrome zero-days has remained high, with this being one of several patched in 2025 alone.

The fixed desktop builds for this Chrome zero-day are:

Platform Fixed Chrome version
Windows 124.0.6367.201/.202
Mac 124.0.6367.201
Linux 124.0.6367.201

If Chrome now offers a newer Stable version, install that newer version instead. The goal is not to stay on a specific version; it is to ensure the browser is at or beyond the fixed release for your platform.


Chrome Zero-Day Raises File and Session Theft Risk

The practical danger is immediate. Such a flaw could be used to steal corporate emails, documents, session cookies, or other sensitive information directly from the browser's memory.

Google has not confirmed a specific theft campaign tied to CVE-2025-4761 or named attackers or targets. The known facts are specific: an exploit exists in the wild, the flaw affects Chrome V8, and crafted HTML can trigger code execution.

Could a normal web page become the attack surface? Yes, if the page is weaponized—through malvertising, a compromised site, or a phishing link—and the browser is vulnerable.

Browser zero-days draw fast attention because Chrome sits between users and almost everything they do online: email, cloud documents, SaaS platforms, and internal tools. A malicious page does not need to look suspicious to create risk.

XOOMAR analysis: The highest priority is any machine where Chrome can access valuable data. Start with devices used for corporate email, financial accounts, developer systems, and administrative panels. The patch cadence for 2025 reinforces that these threats are not theoretical but operational realities.

Google’s limited disclosure leaves important investigative gaps for defenders. However, that uncertainty underscores the directive for users: update first, investigate second.


How to Confirm Your Chrome Browser Has the Zero-Day Patch Installed

Chrome usually updates automatically, but the patch is not active until the browser restarts. The safest action is to check manually and relaunch.

Use this path:

  1. Open Chrome.
  2. Go to settings: Type chrome://settings/help in the address bar and press Enter.
  3. Let Chrome check: The browser will search for and install any available updates.
  4. Relaunch Chrome: The patch does not fully take effect until the browser restarts. Click "Relaunch."

Which devices need attention? All of them. Check work laptops, personal machines, shared desktops, and secondary Chrome profiles.

For security teams, the priority is fleet confirmation. Verify that endpoints have moved to at least 124.0.6367.201 (or newer) and identify machines where an update is pending a restart.

Admins must also check Chromium-based browsers separately, including Microsoft Edge, Brave, Vivaldi, and Opera. Chrome’s update does not patch these browsers; each vendor must ship its own fixed build.

After patching, users who may have visited suspicious pages should monitor for unusual account activity, especially for high-value sessions. Security teams should review relevant logs for signs of compromise.

Key Takeaways

  • Attackers were already exploiting CVE-2025-4761 in the wild when Google issued the Chrome fix.
  • The type confusion flaw in the V8 engine affects Chrome desktop users on Windows, Mac, and Linux.
  • Users and IT teams must install the latest available Chrome Stable build and confirm the browser has relaunched for the patch to be active.
  • This exploit underscores the critical need for prompt updates as a core security practice.

Chrome zero-day severity score

CVE-2026-11645
/108.8
XOOMAR

Written by

XOOMAR Insights Team

Research and Editorial Desk

The XOOMAR Insights Team pairs automated research with human editorial judgment. We track hundreds of sources across technology, fintech, trading, SaaS, and cybersecurity, cross-check the facts, and explain what happened, why it matters, and what to watch next. We do not just rewrite headlines. Every article is fact-checked and scored for reliability before it goes live, and we link back to the original sources so you can verify anything yourself.

Related Articles

Close-up of Scrabble tiles spelling 'data breach' on a blurred backgroundCybersecurity

Routine Chrome 151 Patch Masks Software's Skeletal Truth

Chrome 151 patched 41 critical flaws as part of routine updates, but misleading headlines have conflated it with a separate, dangerous zero-day patch, revealing

Aug 7, 20266 min
Wooden tiles spelling 'phishing' highlight cybersecurity themes.Cybersecurity

Attackers Hijack Email AI for CEO Fraud Heists

New research simulates how attackers hijack a compromised user's sanctioned email AI assistant to run reconnaissance, hide alerts, and craft executive impersona

Aug 4, 20265 min
Chain-locked book, phone, and laptop symbolizing digital and intellectual security.Cybersecurity

OpenAI Unchains Its AI for 95% of Cyber Attacks

OpenAI's new cybersecurity AI model dramatically reduces safety refusals, completing 95% of attack simulations, marking a major policy shift toward empowering a

Aug 11, 20266 min
AI chip protected by a glowing cybersecurity alliance network, with closed labs in the distance.Cybersecurity

Nvidia AI Security Alliance Leaves OpenAI Off Roster

Nvidia's 37-member AI security push puts open tools against closed labs, with OpenAI, Anthropic and Google missing from the launch.

Jul 27, 20267 min
Person holding tablet with VPN connection screen for secure internet browsing.Cybersecurity

Windows and macOS Users Face Hidden Security Gaps in 2026

While operating system security has improved, blind spots persist. Specific threat vectors still exploit them.

Aug 13, 202615 min
A dynamic forex trading floor scene showing intense focus on a glowing EUR/USD chart at a critical technical level.Trading

Euro Hits Multi-Year Wall in ECB Showdown

The euro's rally hit a brick wall at the 200-day moving average, setting up a decisive showdown with Thursday's European Central Bank monetary policy meeting.

Sep 9, 20266 min
A futuristic AI interface in a sleek supermarket hub, visualizing chat prompts being translated dynamically into a digital grocery cart.Technology

Instacart Ends Grocery Scrolling With AI Concierge Clementine

Instacart released Clementine, an AI assistant that turns casual chat prompts like 'kid lunches for a week' into a fully built, ready-to-checkout grocery order.

Sep 9, 20268 min
Hurricane winds and torrential rain batter tropical coastline, illustrating infrastructure vulnerability during extreme weather events.Global Trends

Hurricane Lowell Cuts Power to 30,000 on Kauai

Hurricane Lowell's offshore winds knocked out power for 30,000 residents on Kauai, showcasing how vulnerable critical infrastructure is even without a direct la

Sep 9, 20268 min
Aerial view of hurricane aftermath on tropical island coastline with scattered debris and flooded infrastructure under dramatic skies.Global Trends

Kauai Left Powerless As Hurricane Lowell Skirts Islands

Hurricane Lowell passed west of Hawaii but crippled Kauai with near-total power loss and severe flooding, demonstrating the storm's wide, destructive reach.

Sep 9, 20264 min
A cinematic shot inside a high-tech financial data center, with abstract light visualizations representing volatile currency markets.Fintech

Poland's Final Inflation Bet Pays Off or Blows Up Soon

A massive bet on Polish rate hikes is clashing with central bank inaction, creating a volatile mispricing that could force a violent correction in the EUR/PLN p

Sep 9, 20267 min

Don't miss the signal

Get our weekly roundup of the stories that matter across tech, fintech, and trading. No noise, just signal.

Free forever. No spam. Unsubscribe anytime.