{"id":302248,"date":"2025-11-20T01:41:08","date_gmt":"2025-11-20T01:41:08","guid":{"rendered":"https:\/\/www.newsbeep.com\/us\/302248\/"},"modified":"2025-11-20T01:41:08","modified_gmt":"2025-11-20T01:41:08","slug":"attacks-confirmed-google-issues-emergency-update-for-2-billion-chrome-users","status":"publish","type":"post","link":"https:\/\/www.newsbeep.com\/us\/302248\/","title":{"rendered":"Attacks Confirmed\u2014Google Issues Emergency Update For 2 Billion Chrome Users"},"content":{"rendered":"<p><img decoding=\"async\" class=\" top-image\" src=\"https:\/\/www.newsbeep.com\/us\/wp-content\/uploads\/2025\/11\/1763602868_683_0x0.jpg\" alt=\"Google Chrome app\" data-height=\"3507\" data-width=\"5272\" fetchpriority=\"high\" style=\"position:absolute;top:0\"\/><\/p>\n<p>Chrome emergency update confirmed <\/p>\n<p>dpa\/picture alliance via Getty Images<\/p>\n<p>Updated Nov. 19 with confirmation that America\u2019s cyber defense agency has issued an update deadline for Chrome users given the severity of this new zero day.<\/p>\n<p>Google has <a class=\"color-link\" href=\"https:\/\/chromereleases.googleblog.com\/search\/label\/Desktop%20Update\" target=\"_blank\" rel=\"nofollow noopener noreferrer\" data-ga-track=\"ExternalLink:https:\/\/chromereleases.googleblog.com\/search\/label\/Desktop%20Update\" aria-label=\"suddenly warned\">suddenly warned<\/a> that attacks on Chrome are underway, issuing an emergency update for all desktop users. \u201cGoogle is aware that an exploit for <a class=\"color-link\" href=\"https:\/\/www.tenable.com\/cve\/CVE-2025-13223\" target=\"_blank\" rel=\"nofollow noopener noreferrer\" data-ga-track=\"ExternalLink:https:\/\/www.tenable.com\/cve\/CVE-2025-13223\" aria-label=\"CVE-2025-13223\">CVE-2025-13223<\/a> exists in the wild,\u201d the company confirmed on Monday.<\/p>\n<p>The vulnerability \u2014 a \u201cType Confusion in V8\u201d \u2014 was discovered by Google\u2019s own Threat Analysis Group last week. This fix has been rushed out, highlighting its seriousness.<\/p>\n<p>That severity has now been underlined by America\u2019s cyber defense agency mandating federal staff to update or to stop using Chrome. <a class=\"color-link\" href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog\" target=\"_blank\" rel=\"nofollow noopener noreferrer\" data-ga-track=\"ExternalLink:https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog\" aria-label=\"CISA\">CISA<\/a> added CVE-2025-13223 to its Known Exploited Vulnerability (KEV) catalog on Nov. 19, and has confirmed a Dec. 10 deadline for federal agency users to update or \u201cdiscontinue use of the product.\u201d<\/p>\n<p><a class=\"embed-base color-body color-body-border link-embed embed-1\" href=\"https:\/\/www.forbes.com\/sites\/zakdoffman\/2025\/11\/18\/has-samsung-installed-unremovable-israeli-spyware-on-your-phone\/\" target=\"_blank\" aria-label=\"Has Samsung Installed \u2018Unremovable Israeli Spyware\u2019 On Your Phone?\" data-ga-track=\"forbesEmbedly:https:\/\/www.forbes.com\/sites\/zakdoffman\/2025\/11\/18\/has-samsung-installed-unremovable-israeli-spyware-on-your-phone\/\" rel=\"nofollow noopener\">ForbesHas Samsung Installed \u2018Unremovable Israeli Spyware\u2019 On Your Phone?By Zak Doffman<\/a><\/p>\n<p>While CISA\u2019s formal update order is only for federal staff, its mandate is \u201cfor the benefit of the cybersecurity community and network defenders\u2014and to help every organization better manage vulnerabilities and keep pace with threat activity.\u201d<\/p>\n<p>As such, all Chrome users should update their browsers now. The update should download automatically, but you will need to <a class=\"color-link\" href=\"https:\/\/www.google.com\/chrome\/update\/\" target=\"_blank\" rel=\"nofollow noopener noreferrer\" data-ga-track=\"ExternalLink:https:\/\/www.google.com\/chrome\/update\/\" aria-label=\"restart your browser\">restart your browser<\/a> to ensure it installs and takes effect. Your regular tabs will reload, but your private \u201cincognito\u201d tabs will not.<\/p>\n<p>Despite there being a lack of more details information on this latest zero day threat, the type of flaw can enable a remote attacker to destabilize a system or run their own arbitrary code to exfiltrate data or push malicious software onto a target device.<\/p>\n<p>These types of flaws can also be chained with other vulnerabilities to provide an initial entry point to a device or the network on which that device sits. <\/p>\n<p>Per <a class=\"color-link\" href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2025-13223\" target=\"_blank\" rel=\"nofollow noopener noreferrer\" data-ga-track=\"ExternalLink:https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2025-13223\" aria-label=\"NIST\">NIST<\/a>, this \u201cType Confusion in V8 in Google Chrome prior to 142.0.7444.175 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.\u201d The vulnerability has been issued a high-severity rating.<\/p>\n<p><a class=\"embed-base color-body color-body-border link-embed embed-2\" href=\"https:\/\/www.forbes.com\/sites\/zakdoffman\/2025\/11\/18\/upgrade-now-microsoft-warns-as-urgent-windows-update-confirmed\/\" target=\"_blank\" aria-label=\"\u2018Upgrade Now,\u2019 Microsoft Warns As Urgent Windows Update Confirmed\" data-ga-track=\"forbesEmbedly:https:\/\/www.forbes.com\/sites\/zakdoffman\/2025\/11\/18\/upgrade-now-microsoft-warns-as-urgent-windows-update-confirmed\/\" rel=\"nofollow noopener\">Forbes\u2018Upgrade Now,\u2019 Microsoft Warns As Urgent Windows Update ConfirmedBy Zak Doffman<\/a><\/p>\n<p>As ever, Google also says \u201caccess to bug details and links may be kept restricted until a majority of users are updated with a fix. We will also retain restrictions if the bug exists in a third party library that other projects similarly depend on, but haven\u2019t yet fixed.\u201d<\/p>\n<p>The update brings Chrome\u2019s stable channel up to 142.0.7444.175\/.176 for Windows and 142.0.7444.176 for Mac. For Linux it\u2019s 142.0.7444.175. While Google\u2019s boilerplate says \u201croll out over the coming days\/weeks,\u201d you can expect the update today.<\/p>\n<p>While Google Chrome zero days are a regular event, Google takes immense credit for the speed with which fixes are developed and deployed. It goes without saying that all users should update their browsers as soon as they see the restart flag. <\/p>\n","protected":false},"excerpt":{"rendered":"Chrome emergency update confirmed dpa\/picture alliance via Getty Images Updated Nov. 19 with confirmation that America\u2019s cyber defense&hellip;\n","protected":false},"author":2,"featured_media":302249,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[31],"tags":[157126,157129,157127,157128,157130,74],"class_list":{"0":"post-302248","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-technology","8":"tag-chrome-attack","9":"tag-chrome-attacks-wild","10":"tag-chrome-emergency-update","11":"tag-chrome-update-now","12":"tag-chrome-zero-day","13":"tag-technology"},"_links":{"self":[{"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/posts\/302248","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/comments?post=302248"}],"version-history":[{"count":0,"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/posts\/302248\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/media\/302249"}],"wp:attachment":[{"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/media?parent=302248"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/categories?post=302248"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/tags?post=302248"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}