This story is from January 26, 2025
Government has a Google Chrome warning for Windows and Mac users
India's cybersecurity watchdog, CERT-In, has warned about two vulnerabilities in the popular Google Chrome browser that hackers can exploit. These new warnings are for Chrome users mostly across Mac, PC and laptop platforms and not that much for smartphone users. These vulnerabilities can allow attackers to compromise user data and devices, highlighting the importance of updating to the latest version of the browser. CERT-In has asked users to immediately apply the necessary security patches and update their Chrome browser to mitigate these risks.
According to CERT-In’s website, Google Chrome is currently facing two major vulnerabilities — CIVN-2025-0007 and CIVN-2025-0008 — which have a severity rating of critical and high, respectively.
The first vulnerability affects Google Chrome versions before 132.0.6834.83/8r (in Windows/ Mac) while the other one targets Google Chrome versions before 132.0.6834.110/111 for Windows and Macs as well as versions before 132.0.6834.110 for Linux.
CIVN-2025-0007 includes multiple vulnerabilities that have been reported in Google Chrome which could allow a remote attacker to execute arbitrary code, cause Denial of service conditions, disclose sensitive information, and bypass security restrictions on the targeted system. These security flaws are targeted towards all end-user organisations and individuals using Google Chrome for desktops. Hackers can use these vulnerabilities to potentially disclose sensitive information, cause system instability and data exfiltration.
CERT-In claimed that these vulnerabilities exist in Google Chrome due to out-of-bounds memory access in V8, inappropriate implementation in navigation, fullscreen, fenced frames, payments, extensions and compositing, an integer overflow in Skia, out-of-bounds read in metrics, stack buffer overflow in Tracing, Race in Frames and Insufficient data validation in Extensions.
A remote attacker can exploit these vulnerabilities by sending a specially crafted request to the targeted system. Successful exploitation of these vulnerabilities could allow a remote attacker to execute arbitrary code, cause Denial of Service (DoS) conditions, disclose sensitive information, and bypass security restrictions on the targeted systems.
Meanwhile, CIVN-2025-0008 also includes multiple vulnerabilities which could also allow a remote attacker to execute arbitrary code or cause denial of service (DoS) conditions on the targeted system.
These security flaws are also targeted towards all end-user organisations and individuals using Google Chrome for Desktop. Hackers can also use these vulnerabilities to disclose sensitive information or cause system instability.
CERT-In also noted that these vulnerabilities exist in Google Chrome due to object corruption in V8 and out-of-bounds memory access in V8. A remote attacker could exploit these vulnerabilities by executing a specially crafted webpage to conduct remote code execution or cause a denial of service (DoS) condition on the targeted systems.
AI Masterclass for Students. Upskill Young Ones Today!– Join Now
Google Chrome security flaws: What are they
The first vulnerability affects Google Chrome versions before 132.0.6834.83/8r (in Windows/ Mac) while the other one targets Google Chrome versions before 132.0.6834.110/111 for Windows and Macs as well as versions before 132.0.6834.110 for Linux.
How these security flaws can affect users
CIVN-2025-0007 includes multiple vulnerabilities that have been reported in Google Chrome which could allow a remote attacker to execute arbitrary code, cause Denial of service conditions, disclose sensitive information, and bypass security restrictions on the targeted system. These security flaws are targeted towards all end-user organisations and individuals using Google Chrome for desktops. Hackers can use these vulnerabilities to potentially disclose sensitive information, cause system instability and data exfiltration.
A remote attacker can exploit these vulnerabilities by sending a specially crafted request to the targeted system. Successful exploitation of these vulnerabilities could allow a remote attacker to execute arbitrary code, cause Denial of Service (DoS) conditions, disclose sensitive information, and bypass security restrictions on the targeted systems.
Meanwhile, CIVN-2025-0008 also includes multiple vulnerabilities which could also allow a remote attacker to execute arbitrary code or cause denial of service (DoS) conditions on the targeted system.
These security flaws are also targeted towards all end-user organisations and individuals using Google Chrome for Desktop. Hackers can also use these vulnerabilities to disclose sensitive information or cause system instability.
CERT-In also noted that these vulnerabilities exist in Google Chrome due to object corruption in V8 and out-of-bounds memory access in V8. A remote attacker could exploit these vulnerabilities by executing a specially crafted webpage to conduct remote code execution or cause a denial of service (DoS) condition on the targeted systems.
AI Masterclass for Students. Upskill Young Ones Today!– Join Now
Top Comment
S
Sanjay Ambure
205 days ago
hello, tell me how to protect ? Read allPost comment
Popular from Technology
- Kairan Quazi, who joined Elon Musk’s SpaceX as engineer at 14, is leaving; says: I felt…
- Apple to make all iPhone 17 series models for US market in…
- CEO who laid off 80% employees globally for refusing to adopt AI, says after two years that he…
- Apple iPhone 17 Pro Max launch date: Expected timeline, pre-orders, and other details
- Apple founder Steve Jobs lived by the rule that God is in …..
end of article
Trending Stories
03:09 'Scared to go back to India': Truck driver Harjinder Singh who killed 3 in Florida was allowed to stay in US in 2018 on $5,000 bond- Watch: Sikh postman's act of kindness while delivering a package goes viral; Priyanka Chopra among admirers
- Microsoft co-founder Bill Gates on the job he cannot do: I wouldn't enjoy being a ...
- NFL underdog Tyson Bagent shocks Chicago as the Bears suddenly boast the league's best quarterback duo
- Kairan Quazi, who joined Elon Musk’s SpaceX as engineer at 14, is leaving; says: I felt…
- Apple founder Steve Jobs lived by the rule that God is in …
- CEO who laid off 80% employees globally for refusing to adopt AI, says after two years that he…
Featured in technology
- 'Very worried about China', says OpenAI CEO Sam Altman with a warning for America and the new 'China-Safe' chips policy
- The 'OBSESSION' that is hurting Amazon, as its stock falls behind Nasdaq
- Mark Zuckerberg overhauls Meta's AI division amid 'employee tensions'
- You can now play Fortnite on Discord without downloading the game, here’s how
- Nvidia may be developing new AI chip for China: How this may be different from existing H20
- How Google plans to ‘change’ Play Store to avoid future fines in Europe
Visual Stories
- 8 Indian fruits that are best known to prevent cancer cell development
- Bigg Boss Malayalam fame Dilsha Prasannan’s top 10 traditional looks
- 8 ways to style your sheer-net dupatta during the festive season
- Best saree looks of Kannada beauty Rashmi Prabhakar
- Science says these 6 hacks can improve your focus in minutes
Photostories
- Bollywood actors who embraced method acting with fearless dedication forever
- Harvard doctor shares the best vegetables for healing the body inside out
- ‘The Social Network’, ‘Silence’, ‘Never Let Me Go’: A look at Andrew Garfield's powerful performances
- From Priyanka to Yodhitha: Here’s a look at the former winners of Drama Juniors Telugu
- Fun facts you didn't know about 'Param Sundari' actress Janhvi Kapoor
- 5 reasons vultures are nature’s silent protectors
- From Ankita Lokhande to The Great Khali: A look at the highest-paid contestants in Bigg Boss
- 10 BEST states to live in America in 2025: Where life is all smiles
- Most famous Indian dishes around the world
- Matthew Perry’s birth anniversary: Unseen moments with the Friends cast
Top Trends
Up Next