Application security, Threat Intelligence

Google patches trio of Chrome security bugs

Google Chrome application icon on Apple iPhone X screen close-up. Google Chrome app icon. Google Chrome application.

Updates have been released by Google to fix three flaws impacting its Chrome browser, one of which has already been used in attacks, according to Security Affairs.

Additional details regarding the actively exploited high-severity issue, dubbed Chromium issue 466192044, were not provided by Google. However, GitHub-submitted code revealed that the flaw originated from the ANGLE graphics library. In its Metal renderer, buffer sizes were calculated incorrectly, which could cause memory errors, crashes, or possibly let attackers run code. The company said in its advisory that it is "aware that an exploit for 466192044 exists in the wild."

Also addressed were a pair of medium-severity issues, including the use-after-free bug in Password Manager, tracked as CVE-2025-14372, and the improper Toolbar implementation vulnerability, tracked as CVE-2025-14373. Earlier this year, Google dealt with seven other Chrome zero-days, including several type confusion bugs in the V8 engine, input-validation problems in ANGLE and GPU, and an out-of-bounds V8 issue tracked as CVE-2025-5419, CVE-2025-4664, which is a flaw that could allow account takeover, and a Windows-specific Mojo handling problem reported by Kaspersky researchers. Chrome Stable is now updated to versions 143.0.7499.109/.110 across major platforms.

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds