Written By Divya
Edited By: Divya | Published By: Divya | Published: Dec 08, 2025, 09:14 PM (IST)
Also Read: Google Adds New Android Warning To Stop Banking Scams During Phone Calls: How It Works
If your daily browsers include Google Chrome and Microsoft Edge, then the Indian Computer Emergency Response Team (CERT-In) has issued a fresh warning for you, highlighting multiple high-risk security vulnerabilities. Since both browsers run on the Chromium engine, the issues affect millions of users across Windows, macOS and Linux. Also Read: Apple, Google, Samsung Push Back Against Mandatory Location Tracking In India
In its latest vulnerability notes, CERT-In (CIVN-2025-0355 for Chrome and CIVN-2025-0354 for Edge) flagged a series of flaws that could allow attackers to remotely execute code, steal sensitive data, or bypass security protections. Also Read: Always-On Phone Tracking? Apple, Google, Samsung Raises Red Flags
These vulnerabilities stem from issues like type Confusion in the V8 engine and race conditions. Inappropriate implementation across components such as DevTools, Downloads, Google Updater, WebRTC and Split View. Moreover, these vulnerabilities come from the use-after-free bugs in Media Stream and Digital Credentials and bad cast issues in Loader.
Simply put, these bugs could let a malicious website run harmful code on your system without you realising it.
For Google Chrome:
For Microsoft Edge, Stable Channel before 143.0.3650.66 are affected. Anyone running older versions is at risk, and CERT-In has advised organisations and individual users to update immediately.
The concern is that exploiting these flaws doesn’t require much interaction. You simply have to open a malicious webpage or click an unsafe link. Once you open a malicious link, it can lead to a successful attack, which means:
In such cases, updating is one of the important factors that can save you, and it is pretty simple, which takes less than a minute.
For Edge users: