Tech

Chrome patched this bug, but CISA says it’s still actively exploited

Share
Share


  • Google patched a new Chrome bug recently
  • Now, CISA added that vulnerability to KEV, signaling abuse in the wild
  • Federal agencies have three weeks to update Chrome

The US Cybersecurity and Infrastructure Security Agency (CISA) added a new Chrome bug to its Known Exploited Vulnerabilities (KEV) catalog, signalling abuse in the wild, and giving Federal Civilian Executive Branch (FCEB) agencies a deadline to patch things up.

The flaw is tracked as CVE-2025-4664. It was recently discovered by security researchers Solidlab, and is described as an “insufficient policy enforcement in Loader in Google Chrome”. On NVD, it was explained that the bug allowed remote threat actors to leak cross-origin data via a crafted HTML page.

Share

Leave a comment

Leave a Reply

Your email address will not be published. Required fields are marked *