Skip to main content

Chrome Zero-Day Vulnerability (CVE-2025-6554)

BACKGROUND


CVSS Score: Base 8.1 High
 

Google has released a security update to address an actively exploited zero-day vulnerability in the V8
JavaScript engine used in Google Chrome. This vulnerability enables remote code execution (RCE) if
exploited successfully.

IMPACT

  • May allow remote attackers to execute arbitrary code which could result in the execution of
    malicious code, spyware, or conduct further system compromise.
  • May cause memory corruption and crashes.

AFFECTED OPERATING SYSTEMS & FIXED VERSIONS

The vulnerability affects all major platforms running Chrome, including Windows, macOS, and Linux.

 Affected OSFixed Version
1Windows138.0.7204.96 / 138.0.7204.97
2Mac OS138.0.7204.92 / 138.0.7204.93
3Linux138.0.7204.9

RECOMMENDATIONS

Users and administrators are advised to install the latest available Chrome updates accordingly.

REFERENCE
https://chromereleases.googleblog.com/2025/06/stable-channel-update-for-desktop_30.html

https://nvd.nist.gov/vuln/detail/CVE-2025-6554

 

 

About

Brunei Computer Emergency Response Team (BruCERT) was established in 2004 as the national and government CERT to deal with computer-related and internet-related security incidents in Negara Brunei Darussalam.