The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued an alert for a new zero-day vulnerability in Google Chromethat has already been exploited by malicious actors. The vulnerability, listed as CVE-2025-13223, affects the Chromium V8 JavaScript engine and poses a serious threat to millions of users.

This is a flaw that could lead to remote code execution (RCE), data breach , and complete system manipulation through a simple website – a scenario particularly dangerous for government agencies and businesses.
How the vulnerability works – The role of type confusion bugs
CVE-2025-13223 is a type confusion, categorized as CWE-843. Simply put, the browser is tricked into processing data as if it were of a different type than it actually is. This leads to poor heap memory management and allows an attacker to inject malicious commands.
See also: Hackers exploit 7-Zip's RCE vulnerability
Google identified and patched the issue on November 19, 2025, releasing the security update for all Chrome versions prior to 131.0.6778.72. However, since the exploit had already been identified, the warning was unavoidable.
Active exploit before patch – What we know so far
Although details of specific campaigns have not been disclosed, CISA confirmed that hackers are exploiting the vulnerability before the patch is widely available.

The vulnerability was immediately added to the Known Exploited Vulnerabilities (KEV), which requires all US federal agencies to take corrective action by December 10, 2025.
The fact that it is a zero-day means that attacks could be carried out without any warning, through methods such as:
- drive-by downloads,
- malicious scripts on compromised websites,
- phishing campaigns that exploit JavaScript engine weaknesses.
Attackers only need to get the user to visit a specific website — from there, the rest happens silently in the background.
See also: WordPress: Serious vulnerability in the W3 Total Cache plugin
Affected Systems – It's Not Just Chrome That's at Risk
V8, as a JavaScript processing core, is also used by other open source browsers. In addition to Chrome on Windows, macOS, and Linux, the following are also affected:
- Microsoft Edge
- Brave
- Opera
- any other Chromium-based browser has not received the update.
In cloud environments and enterprise networks, the vulnerability can be a "backdoor" for lateral movement, credential theft, or supply chain attacks.
No link to ransomware yet – but the risk is growing
Although no links to ransomware groups, threat analysts believe it is only a matter of time. Zero-days like this often become valuable tools for cybercriminal groups, particularly for:
- phishing kits,
- attacks against browsers on corporate workstations,
- credential breaches via web sessions,
- large-scale attacks on government agencies.
CISA warns that organizations should expect an increase in phishing emails that lead to malicious pages designed to exploit this particular bug.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
See also: Operation WrtHug: Exploiting vulnerabilities to infect EoL ASUS routers

What organizations and users should do – Immediate action
The basic line of defense is clear: immediately update Chrome to the latest available version.
For high security environments, it is also recommended:
1. Alignment with Binding Operational Directive 22-01
Public organizations must follow the guidelines of BOD 22-01, which requires:
- continuous monitoring of vulnerabilities,
- utilization of zero-trust architecture,
- rapid application of patches to critical systems.
2. Implementing Zero Trust principles
Isolating browser processes, using sandboxing, and reducing trust in third-party scripts can significantly limit potential breaches.
3. Temporarily disabling the product in extreme cases
If for technical reasons an immediate upgrade is not possible, CISA suggests as a last resort temporarily disabling the browser on critical endpoints to prevent a possible attack.
