Thursday, January 23, 2025

New Google Chrome Security Warning For 3 Billion Users—Act Now

Must read

There’s a danger that with so many security alerts hitting the headlines, warning apathy can kick in. Yet that would be a mistake, a big one. Whether it’s dealing with the fallout of a billion stolen passwords, hidden malware threats for Gmail and Outlook users or attacks against PayPal accounts, you need to take them all seriously. Which is why you really shouldn’t ignore this latest security alert for billions of Google Chrome web browser users across all platforms except iOS—here’s what you need to know and do.

ForbesNew Password Hack Warning—Act Now If Yours Is On This List

Google Chrome Browser Security Alert

It’s only been a week since the last security update warning for Chrome browser users dropped, and now we are back in the same place again. Google has confirmed that two high-severity security vulnerabilities impacting all users of the application across the Android, Linux, macOS and Windows operating systems have been discovered by external security researchers. As such, Google has taken action to start updating all applications to take Chrome to versions 132.0.6834.110/111 for Windows and Mac, 132.0.6834.110 for Linux, and 132.0.6834.122 for Android. These updates will, Google said, “roll out over the coming days/weeks.” I wouldn’t recommend you wait that long, however, given the nature of the vulnerabilities in question.

The vulnerabilities are:

CVE-2025-0611 which is a heap-based overflow vulnerability that takes the form of an object corruption in the V8 Javascript rendering engine of Chrome. The vulnerability earned a researcher known only as 303f06e3, who disclosed it to Google, a $11,000 bounty.

CVE-2025-0612 which earned Alan Goodman a bounty of $8,000, is an out of bounds memory access vulnerability in the same V8 engine.

The latter, SecurityVulnerability.io experts said, can be “potentially exploited by attackers through a specially crafted HTML page, leading to heap corruption. Such vulnerabilities may allow remote attackers to execute arbitrary code, posing significant security risks to users who visit malicious or compromised web pages,” while the first is so serious that “it is crucial for users to update their browsers to maintain security and prevent exploitation.”

ForbesGoogle’s Chrome Security Update Failure—What You Need To Do Now

Act Now—Update Your Google Chrome Browser Immediately To Stay Secure

Although, as already mentioned, the security updates for Google Chrome will start rolling out soon, it’s not soon enough for me and shouldn’t be for you, either, given the severity of the vulnerabilities concerned. I would, therefore, recommend you kickstart that update process right now. Here’s what you need to do:

Go to the Help|About option in your Google Chrome menu and this will automatically start a check for any updates as well as initiate the download process. However, the most critical part of that process comes after the download and that’s the update activation. To ensure this you must restart your browser, save any tabs you have open, and do that to be protected. The following screenshots show how to update your Google Chrome browser and activate the new security fixes.

ForbesGoogle ‘Perpetual Hack’ Attack Steals Passwords And 2FA—Act Now

Latest article