News: 1765472971

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Google fixes super-secret 8th Chrome 0-day

(2025/12/11)


Google issued an emergency fix for a Chrome vulnerability already under exploitation, which marks the world's most popular browser's eighth zero-day bug of 2025.

We have even fewer than usual details about this security flaw, and the missing details as of early Thursday include a CVE (still listed as "under coordination"), what type of vulnerability Google fixed in Chrome, and who spotted and reported the security hole.

As of now, the high-severity bug is tracked as 466192044, and all the Chocolate Factory [1]said in its security update is: "Google is aware that an exploit for 466192044 exists in the wild."

[2]

Google generally withholds bug details until the majority of its users have updated their browsers, but it does typically provide a CVE and the type of weakness that it fixed.

[3]

[4]

Mac and Windows users should update to 143.0.7499.109/.110 to address the issue, and 143.0.7499.109 is the update for Linux systems.

In addition to plugging 466192044, the latest Chrome update also includes a fix for a medium-severity use-after-free flaw in Password Manager, tracked as CVE-2025-14372 and reported by Weipeng Jiang.

[5]

Plus, another medium-severity security hole, CVE-2025-14373, that's due to inappropriate implementation in Toolbar, now has a fix. Khalil Zhani reported this one.

[6]Google Chrome bug exploited as an 0-day - patch now or risk full system compromise

[7]Two Android 0-day bugs disclosed and fixed, plus 105 more to patch

[8]Microsoft reports 7.8-rated zero day, plus 56 more in December Patch Tuesday

[9]Microsoft quietly shuts down Windows shortcut flaw after years of espionage abuse

Chrome's latest zero-day comes less than a month after Google disclosed and patched its seventh such security issue: [10]CVE-2025-13223 , a type confusion flaw in the V8 JavaScript engine that could potentially lead to full system compromise.

This emergency fix also follows [11]two Android bugs that were exploited as zero-days before being fixed in Android's December update. ®

Get our [12]Tech Resources



[1] https://chromereleases.googleblog.com/2025/12/stable-channel-update-for-desktop_10.html

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/patches&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2aTtNBFep7AKPD7pP5ge37wAAAAo&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/patches&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44aTtNBFep7AKPD7pP5ge37wAAAAo&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/patches&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33aTtNBFep7AKPD7pP5ge37wAAAAo&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/patches&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44aTtNBFep7AKPD7pP5ge37wAAAAo&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[6] https://www.theregister.com/2025/11/18/google_chrome_seventh_0_day/

[7] https://www.theregister.com/2025/12/02/android_0_days/

[8] https://www.theregister.com/2025/12/09/december_2025_patch_tuesday/

[9] https://www.theregister.com/2025/12/04/microsoft_lnk_bug_fix/

[10] https://www.theregister.com/2025/11/18/google_chrome_seventh_0_day/

[11] https://www.theregister.com/2025/12/02/android_0_days/

[12] https://whitepapers.theregister.com/



Anonymous Coward

The bad guys have a working in the wild exploit, but we can't be told what the weakness is....

Just patch and trust us...

IGotOut

Because maybe 1 or 2 bad guys know of it, rather than 1 or 2 thousand?

What about Chromium and derivatives?

cyberdemon

Er, so presumably the same thing affects the open-source Chromium and its derivatives (MS Edge etc)? but Google are keeping it under-wraps.. So does that mean Chromium et al are unable to patch it?

Re: What about Chromium and derivatives?

andyprough

A Brave update is incoming right now, so presumably chromium and its forks have gotten the information and are rolling out their fixes as well.

Chrome is really the new IE....

kmorwath

.... non surprise MS chose it for Edge.

Brillineggiava, ed i tovoli slati
girlavano ghimbanti nella vaba;
i borogovi eran tutti mimanti
e la moma radeva fuorigraba.

"Figliuolo mio, sta' attento al Gibrovacco,
dagli artigli e dal morso lacerante;
fuggi l'uccello Giuggiolo, e nel sacco
metti infine il frumioso Bandifante".
-- Lewis Carroll, "Jabberwocky"