Written By Divya
Also Read: Google Pixel 11, Pixel 11 Pro, Pro XL, Pro Fold: Full specs and prices leaked ahead of launch
If your daily browsers include Google Chrome and Microsoft Edge, then the Indian Computer Emergency Response Team (CERT-In) has issued a fresh warning for you, highlighting multiple high-risk security vulnerabilities. Since both browsers run on the Chromium engine, the issues affect millions of users across Windows, macOS and Linux. Also Read: Google removes AI Satellite image tool within 24 hours of launch
In its latest vulnerability notes, CERT-In (CIVN-2025-0355 for Chrome and CIVN-2025-0354 for Edge) flagged a series of flaws that could allow attackers to remotely execute code, steal sensitive data, or bypass security protections. Also Read: Google expands age verification for Play Store users globally: What it means for users, how to use
These vulnerabilities stem from issues like type Confusion in the V8 engine and race conditions. Inappropriate implementation across components such as DevTools, Downloads, Google Updater, WebRTC and Split View. Moreover, these vulnerabilities come from the use-after-free bugs in Media Stream and Digital Credentials and bad cast issues in Loader.
Simply put, these bugs could let a malicious website run harmful code on your system without you realising it.
For Google Chrome:
For Microsoft Edge, Stable Channel before 143.0.3650.66 are affected. Anyone running older versions is at risk, and CERT-In has advised organisations and individual users to update immediately.
The concern is that exploiting these flaws doesn’t require much interaction. You simply have to open a malicious webpage or click an unsafe link. Once you open a malicious link, it can lead to a successful attack, which means:
In such cases, updating is one of the important factors that can save you, and it is pretty simple, which takes less than a minute.
For Edge users: