More

    Chrome patched this bug, but CISA says it’s still actively exploited




    • Google patched a new Chrome bug recently
    • Now, CISA added that vulnerability to KEV, signaling abuse in the wild
    • Federal agencies have three weeks to update Chrome

    The US Cybersecurity and Infrastructure Security Agency (CISA) added a new Chrome bug to its Known Exploited Vulnerabilities (KEV) catalog, signalling abuse in the wild, and giving Federal Civilian Executive Branch (FCEB) agencies a deadline to patch things up.

    The flaw is tracked as CVE-2025-4664. It was recently discovered by security researchers Solidlab, and is described as an “insufficient policy enforcement in Loader in Google Chrome”. On NVD, it was explained that the bug allowed remote threat actors to leak cross-origin data via a crafted HTML page.

    https://cdn.mos.cms.futurecdn.net/8Mw3Yhi8NZMR44GH526arM.jpg



    Source link

    Latest articles

    spot_imgspot_img

    Related articles

    Leave a reply

    Please enter your comment!
    Please enter your name here

    spot_imgspot_img