Google Patches Actively Exploited Chrome V8 Zero-Day — CVE-2026-4425

Critical type confusion vulnerability in Chrome V8 engine exploited in targeted attacks. Google urges immediate browser updates across all platforms.

Google has released an emergency security update for Chrome to address CVE-2026-4425, a critical type confusion vulnerability in the V8 JavaScript engine that is being actively exploited in targeted attacks. The vulnerability allows remote code execution in the browser sandbox.

Google's Threat Analysis Group (TAG) has confirmed that the exploit is being used in highly targeted campaigns against specific individuals, likely by sophisticated threat actors. While the attack volume is currently limited, the severity of the vulnerability and the availability of exploit code make widespread exploitation a significant concern.

Users are urged to update Chrome immediately across all platforms (Windows, macOS, Linux, and Android). Enterprise organizations should use Chrome Browser Cloud Management to enforce rapid deployment of the security update across managed devices.

Source: Google Chrome Security