Tech

Chrome patched this bug, but CISA says it’s still actively exploited

Share
Share


  • Google patched a new Chrome bug recently
  • Now, CISA added that vulnerability to KEV, signaling abuse in the wild
  • Federal agencies have three weeks to update Chrome

The US Cybersecurity and Infrastructure Security Agency (CISA) added a new Chrome bug to its Known Exploited Vulnerabilities (KEV) catalog, signalling abuse in the wild, and giving Federal Civilian Executive Branch (FCEB) agencies a deadline to patch things up.

The flaw is tracked as CVE-2025-4664. It was recently discovered by security researchers Solidlab, and is described as an “insufficient policy enforcement in Loader in Google Chrome”. On NVD, it was explained that the bug allowed remote threat actors to leak cross-origin data via a crafted HTML page.

Share

Leave a comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Related Articles
From fertilizer to energy source of the future
Tech

From fertilizer to energy source of the future

Fraunhofer IMM pilot plant for ammonia cracking with ammonia cracking capaci-ty of...

Reducing energy consumption with phase change materials
Tech

Reducing energy consumption with phase change materials

Production of PCM emulsions in the lab. Credit: Fraunhofer ISE Water has...

Google Gemini is set to become a significantly better phone assistant thanks to these two small upgrades
Tech

Google Gemini is set to become a significantly better phone assistant thanks to these two small upgrades

Google Gemini can more easily access your Phone and Messages apps Previously,...

New technique can make AI ‘see’ whatever you want
Tech

New technique can make AI ‘see’ whatever you want

Credit: AI-generated image Researchers have demonstrated a new way of attacking artificial...