HomeSecurityChrome 138 update fixes Zero-Day vulnerability

Chrome 138 update fixes zero-day vulnerability

Google on Monday announced the new Chrome 138 update, which fixes a high-severity zero-day vulnerability for which there is already an active exploit online.

See also: Chrome security update: 11 vulnerabilities fixed

Chrome 138

The vulnerability, identified as CVE-2025-6554 , is described as a “ type confusion ” in the V8 JavaScript and WebAssembly engines , which are open source software.

Errors of this kind, related to memory safety, can be exploited to cause unexpected software behavior, such as crashes, remote code execution, or other types of attacks.

According to NIST, successful exploitation of this vulnerability could allow remote attackers to perform arbitrary read/write operations via specially crafted HTML pages. Google also notes that the vulnerability was reported on June 25th and that the mitigations were implemented the following day.

Although Google has not provided detailed information about the vulnerability or exploit observed, the wording of the announcement and the speed with which the patch was released suggest that the security flaw has already been actively exploited.

See also: Google fixes new zero-day vulnerability in Chrome browser

The internet giant also credited Clement Lecigne from Google's Threat Analysis Team (TAG) for reporting the issue. TAG researchers have uncovered several vulnerabilities that have been exploited by commercial spyware vendors, including similar security holes in the Chrome browser.

Zero-Day vulnerability

The latest version of Chrome is now gradually available with build numbers 138.0.7204.96/.97 for Windows, 138.0.7204.92/.93 for macOS, and 138.0.7204.96 for Linux. Users are advised to update their browser immediately.

This is the fourth Chrome vulnerability reported this year for which Google confirms the existence of an exploit, following CVE-2025-2783, CVE-2025-4664 , and CVE-2025-5419.

See also: Chrome vulnerabilities allow malicious code execution

Google, through its Threat Analysis Group (TAG), plays a critical role in uncovering such threats. The fact that four incidents of active exploits on Chrome have already been recorded in 2025 is an indication of how targeted this particular browser is, given its huge use worldwide. That is why it is extremely important for users to always keep their software up to date — especially their browsers — as security updates fix vulnerabilities that can lead to serious privacy breaches or even data loss.

Source: securityweek

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS