According to the CERT-In advisory, this vulnerability arises due to an incorrect implementation in Chrome's V8 JavaScript engine.
Highlights
A high-severity 'remote code execution' vulnerability has been discovered in Chrome
This vulnerability has been found in Chrome versions older than 141.0.7390.122.123
Google confirmed the bug and said it would release a patch.
India's cyber security agency CERT-In has issued a new warning for Google Chrome users. The agency has reported a high-severity 'Remote Code Execution' (RCE) vulnerability (CIVN-2025-0274) affecting older and unpatched Chrome versions. By exploiting this vulnerability, attackers can gain remote access to a user's system, posing a risk of data theft, system takeover, or service disruption. This vulnerability has been found in versions of Chrome older than 141.0.7390.122.123.
According to CERT-In's advisory , this vulnerability arises due to an incorrect implementation of Chrome's V8 JavaScript engine, which is responsible for executing JavaScript in Chrome. According to the report, a remote attacker could exploit this vulnerability by sending a specially crafted web request and trigger unintended program behavior.
If this attack is successful, the attacker could run arbitrary code on the user's system, potentially leading to a system takeover or gaining access to sensitive data. CERT-In says this could lead to widespread service disruption or data theft, especially if access is being gained from a system administrator account.
Google has confirmed the bug and stated that a fix has been included in the stable channel update for desktop, which began rolling out on October 21, 2025. The updated version numbers are 141.0.7390.122.123 (for Windows and macOS) and 141.0.7390.122 (for Linux). The company has stated that this update will reach all users in the coming days.
CERT-In advises all users and organizations to immediately update to the latest version of Chrome and enable automatic updates to prevent future attacks. The agency also advises users to manually check for updates by going to Help > About Google Chrome.
