惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

P
Proofpoint News Feed
云风的 BLOG
云风的 BLOG
Apple Machine Learning Research
Apple Machine Learning Research
Hugging Face - Blog
Hugging Face - Blog
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
Google DeepMind News
Google DeepMind News
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
雷峰网
雷峰网
B
Blog
月光博客
月光博客
博客园 - 【当耐特】
WordPress大学
WordPress大学
Microsoft Azure Blog
Microsoft Azure Blog
I
InfoQ
The GitHub Blog
The GitHub Blog
Engineering at Meta
Engineering at Meta
Jina AI
Jina AI
博客园 - Franky
MyScale Blog
MyScale Blog
H
Hackread – Cybersecurity News, Data Breaches, AI and More
Last Week in AI
Last Week in AI
B
Blog RSS Feed
H
Help Net Security

The Register - Security: Patches

Homeland security cybercops say patch TrueConf (Russia Microsoft Defender for Endpoint leaves some Linux boxes defenseless after update Year-long Russian attacks infect users as soon as they look at an email Cisco SD-WAN make-me-root bug under attack Ivanti tells Sentry customers to patch now as critical bugs hit 10.0 and 9.9 AI is making Patch Tuesday (kinda) fun again Anthropic to release Mythos-class models to the public Clear your calendar, Drupal user: You have a critically urgent patch to install Welcome to the vulnpocalypse, as vendors use AI to find bugs and patches multiply like rabbits Doozy of a Patch Tuesday includes 30 critical Microsoft CVEs Critical cPanel, WHM flaw probs exploited as 0-day, pros say Microsoft patch fell short. New Windows flaw exploited More Cisco SD-WAN bugs battered in attacks Critical Fortinet sandbox bugs allow auth bypass and RCE Ancient Excel bug comes out of retirement for active attacks Microsoft's massive Patch Tuesday: It's raining bugs Ransomware scum, other crims exploit 4 old Microsoft bugs Attackers exploited the FortiClient EMS bug as a 0-day Citrix NetScaler bug may be multiple flaws in one Ransomware crims abused Cisco 0-day weeks before disclosure Google rushes Chrome update to fix zero-days under attack CISA warns max-severity n8n bug is being exploited in the wild Cisco warns of two more SD-WAN bugs under active attack LexisNexis Legal & Professional confirms data breach Five Eyes warn: Patch your Cisco SD-WAN or risk root takeover Patch these 4 critical, make-me-root SolarWinds bugs ASAP Attacker gets into France's DB listing all bank accounts CISA gives feds 3 days to patch actively exploited Dell bug CISA gives feds 3 days to patch actively exploited Dell bug Google fixes exploited Chrome CSS zero-day
Google fixes super-secret 8th Chrome 0-day
Jessica Lyons Jessica Lyons · 2025-12-12 · via The Register - Security: Patches

Patches

No details, no CVE, update your browser now

Google issued an emergency fix for a Chrome vulnerability already under exploitation, which marks the world's most popular browser's eighth zero-day bug of 2025.

We have even fewer than usual details about this security flaw, and the missing details as of early Thursday include a CVE (still listed as "under coordination"), what type of vulnerability Google fixed in Chrome, and who spotted and reported the security hole. 

As of now, the high-severity bug is tracked as 466192044, and all the Chocolate Factory said in its security update is: "Google is aware that an exploit for 466192044 exists in the wild."

Google generally withholds bug details until the majority of its users have updated their browsers, but it does typically provide a CVE and the type of weakness that it fixed.

Mac and Windows users should update to 143.0.7499.109/.110 to address the issue, and 143.0.7499.109 is the update for Linux systems.

In addition to plugging 466192044, the latest Chrome update also includes a fix for a medium-severity use-after-free flaw in Password Manager, tracked as CVE-2025-14372 and reported by Weipeng Jiang.

Plus, another medium-severity security hole, CVE-2025-14373, that's due to inappropriate implementation in Toolbar, now has a fix. Khalil Zhani reported this one.

Chrome's latest zero-day comes less than a month after Google disclosed and patched its seventh such security issue: CVE-2025-13223, a type confusion flaw in the V8 JavaScript engine that could potentially lead to full system compromise.

This emergency fix also follows two Android bugs that were exploited as zero-days before being fixed in Android's December update. ®