Chrome Zero-Day Vulnerability (CVE-2025-6554)
BACKGROUND
CVSS Score: Base 8.1 High
Google has released a security update to address an actively exploited zero-day vulnerability in the V8
JavaScript engine used in Google Chrome. This vulnerability enables remote code execution (RCE) if
exploited successfully.
IMPACT
- May allow remote attackers to execute arbitrary code which could result in the execution of
malicious code, spyware, or conduct further system compromise. - May cause memory corruption and crashes.
AFFECTED OPERATING SYSTEMS & FIXED VERSIONS
The vulnerability affects all major platforms running Chrome, including Windows, macOS, and Linux.
| Affected OS | Fixed Version | |
| 1 | Windows | 138.0.7204.96 / 138.0.7204.97 |
| 2 | Mac OS | 138.0.7204.92 / 138.0.7204.93 |
| 3 | Linux | 138.0.7204.9 |
RECOMMENDATIONS
Users and administrators are advised to install the latest available Chrome updates accordingly.
REFERENCE
https://chromereleases.googleblog.com/2025/06/stable-channel-update-for-desktop_30.html
https://nvd.nist.gov/vuln/detail/CVE-2025-6554