Google has released security updates for its Chrome browserto address four vulnerabilities, including a zero-day that has already been used in real attacks.

The zero-day vulnerability is tracked as CVE-2025-10585 and is described as a Type Confusion in the V8 JavaScript and WebAssembly engines.
Such vulnerabilities can have serious consequences, as they can be used by malicious actors to cause unpredictable software behavior, resulting in arbitrary code execution and program crashes.
The Google Threat Analysis Group (TAG) discovered and reported the issue on September 16, 2025.
See also: Critical vulnerability in WatchGuard allows code execution
As usual, the company did not share any additional details about how the vulnerability is being used in actual attacks, by whom, or the scale of these attempts. This is to prevent other malicious actors before users can apply a fix.
CVE-2025-10585 is the seventh zero-day vulnerability in Chrome, since the beginning of the year. The other six are: CVE-2025-2783, CVE-2025-4664, CVE-2025-5419, CVE-2025-6554, CVE-2025-6558 and CVE-2025-10585.
The CVE-2025-10585 vulnerability poses a serious security threat to users of Chrome and other Chromium-based browsers. By releasing these updates, Google seeks to protect millions of users from potential attacks that could exploit this vulnerability.
The V8 engine, which is Chrome's core for executing JavaScript and WebAssembly, is critical to the browser's performance and security. Exploiting a vulnerability in this engine could have devastating consequences, allowing malicious users to execute arbitrary code and gain access to sensitive data.
Google, through the Threat Analysis Team, continues to work tirelessly to identify and address such vulnerabilities, ensuring its users remain protected from the latest threats.
See also: Bitpixie vulnerability allows bypass of BitLocker encryption

Users are urged to immediately update their browsers to ensure they are protected from this and other vulnerabilities fixed with the latest update. Regularly updating systems and applications is critical to maintaining security in the digital world.
Google Chrome: Fixes and other vulnerabilities
Google is addressing three additional high‑risk bugs that were discovered by independent cybersecurity researchers.
The first issue, codenamed CVE-2025-10500 , was found in Dawn , a graphics abstraction layer, and involves a use-after-free vulnerability . The second issue, CVE-2025-10501 , involves a similar use-after-free vulnerability , this time in WebRTC , the subsystem that enables real-time communication through Chrome.
The third vulnerability, CVE-2025-10502, is related to a heap buffer overflow in ANGLE, a library that acts as a translator for graphics commands. As the experts explain, both use-after-free and heap overflows can lead to memory corruption and, in severe cases, allow arbitrary code execution on the user's system.
For the discovery of two of the above bugs, Google offered bug bounties worth a total of $25,000 ($15,000 and $10,000 respectively), thus rewarding the contribution of the research community.
See also: Critical vulnerabilities in Chaos Mesh allow RCE attacks

High risk for unpatched systems
Google recommends that all users—regardless of operating system (Windows, macOS, or Linux)—upgrade immediately.
To check the version of Chrome you are using and install the latest update:
- Go to the "Help" menu .
- Select "About Google Chrome".
- The browser will automatically download the available update and will request a restart to apply it.
Target of continuous attacks
In 2025, Chrome has been at the center of several security incidents, with Google forced to patch multiple vulnerabilities (including zero-days) that were used in real-world attacks. The frequency with which such bugs appear is a reminder that browsers—as the most exposed applications on the web—remain a top target for cybercriminals.
Timely installation of updates is not just a recommendation, but a necessary protective measure for every user who wants to safeguard their personal data and the integrity of their system.
