Google released urgent security updates to address a critical vulnerability in Chrome that could allow attackers to take over user accounts through exploitation. The vulnerability has a known public exploit, and patches are now available for users worldwide.
Affected: Google Chrome users on Windows, Linux, and macOS.
Affected: Google Chrome users on Windows, Linux, and macOS.
Keypoints
- Google rapidly released security patches for a high-severity Chrome vulnerability (CVE-2025-4664).
- The bug involves insufficient policy enforcement in Chromeβs Loader component, enabling data leaks via malicious HTML.
- Attackers can exploit the flaw to steal cross-origin data, including sensitive query parameters like OAuth tokens.
- Exploited in the wild, this vulnerability poses a significant risk of account compromise and data theft.
- Chrome users are advised to update their browsers immediately to mitigate potential attacks.