Google fixes super-secret 8th Chrome 0-day
- Reference: 1765472971
- News link: https://www.theregister.co.uk/2025/12/11/google_fixes_supersecret_8th_chrome/
- Source link:
We have even fewer than usual details about this security flaw, and the missing details as of early Thursday include a CVE (still listed as "under coordination"), what type of vulnerability Google fixed in Chrome, and who spotted and reported the security hole.
As of now, the high-severity bug is tracked as 466192044, and all the Chocolate Factory [1]said in its security update is: "Google is aware that an exploit for 466192044 exists in the wild."
[2]
Google generally withholds bug details until the majority of its users have updated their browsers, but it does typically provide a CVE and the type of weakness that it fixed.
[3]
[4]
Mac and Windows users should update to 143.0.7499.109/.110 to address the issue, and 143.0.7499.109 is the update for Linux systems.
In addition to plugging 466192044, the latest Chrome update also includes a fix for a medium-severity use-after-free flaw in Password Manager, tracked as CVE-2025-14372 and reported by Weipeng Jiang.
[5]
Plus, another medium-severity security hole, CVE-2025-14373, that's due to inappropriate implementation in Toolbar, now has a fix. Khalil Zhani reported this one.
[6]Google Chrome bug exploited as an 0-day - patch now or risk full system compromise
[7]Two Android 0-day bugs disclosed and fixed, plus 105 more to patch
[8]Microsoft reports 7.8-rated zero day, plus 56 more in December Patch Tuesday
[9]Microsoft quietly shuts down Windows shortcut flaw after years of espionage abuse
Chrome's latest zero-day comes less than a month after Google disclosed and patched its seventh such security issue: [10]CVE-2025-13223 , a type confusion flaw in the V8 JavaScript engine that could potentially lead to full system compromise.
This emergency fix also follows [11]two Android bugs that were exploited as zero-days before being fixed in Android's December update. ®
Get our [12]Tech Resources
[1] https://chromereleases.googleblog.com/2025/12/stable-channel-update-for-desktop_10.html
[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/patches&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2aTtNBFep7AKPD7pP5ge37wAAAAo&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/patches&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44aTtNBFep7AKPD7pP5ge37wAAAAo&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/patches&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33aTtNBFep7AKPD7pP5ge37wAAAAo&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/patches&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44aTtNBFep7AKPD7pP5ge37wAAAAo&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[6] https://www.theregister.com/2025/11/18/google_chrome_seventh_0_day/
[7] https://www.theregister.com/2025/12/02/android_0_days/
[8] https://www.theregister.com/2025/12/09/december_2025_patch_tuesday/
[9] https://www.theregister.com/2025/12/04/microsoft_lnk_bug_fix/
[10] https://www.theregister.com/2025/11/18/google_chrome_seventh_0_day/
[11] https://www.theregister.com/2025/12/02/android_0_days/
[12] https://whitepapers.theregister.com/
Because maybe 1 or 2 bad guys know of it, rather than 1 or 2 thousand?
What about Chromium and derivatives?
Er, so presumably the same thing affects the open-source Chromium and its derivatives (MS Edge etc)? but Google are keeping it under-wraps.. So does that mean Chromium et al are unable to patch it?
Re: What about Chromium and derivatives?
A Brave update is incoming right now, so presumably chromium and its forks have gotten the information and are rolling out their fixes as well.
Chrome is really the new IE....
.... non surprise MS chose it for Edge.
The bad guys have a working in the wild exploit, but we can't be told what the weakness is....
Just patch and trust us...