Chrome Zero-Day Vulnerabilities Exploited and Patched in 2025
Google addressed a series of eight actively exploited zero-day vulnerabilities in its Chrome browser throughout 2025, with several of these flaws classified as high severity and posing significant risks to billions of users. The vulnerabilities primarily targeted critical components such as the V8 JavaScript engine, WebGPU, ANGLE graphics abstraction layer, Mojo inter-process communication framework, and Chrome’s Loader component. These flaws were exploited by sophisticated threat actors, including state-sponsored groups and commercial surveillance vendors, prompting Google to issue emergency updates and CISA to add all eight vulnerabilities to its Known Exploited Vulnerabilities catalog, mandating urgent remediation.
The V8 JavaScript and WebAssembly engine was the most frequently targeted, accounting for half of the zero-days, while memory corruption issues in both V8 and WebGPU were specifically highlighted in emergency updates. The rapid response from Google’s Threat Analysis Group and the inclusion of these vulnerabilities in federal remediation directives underscore the critical nature of these exploits and the ongoing threat landscape facing Chrome users worldwide.

Get ahead of threats like this
Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
How this story unfolded
3 events from the most recent confirmed update back to the earliest known activity.
Google issues emergency Chrome update for WebGPU and V8 flaws
Google released an emergency Chrome update to fix high-severity memory corruption vulnerabilities in the browser's WebGPU and V8 components. The flaws could have enabled malicious exploitation such as remote code execution or browser compromise.
Google patches eight actively exploited Chrome zero-days during 2025
Throughout 2025, Google released fixes for eight high-severity Chrome zero-day vulnerabilities that were being actively exploited. The flaws affected components including V8, ANGLE, Mojo IPC, and the Loader, with discoveries attributed mainly to Google Threat Analysis Group and, in some cases, Kaspersky and Apple.
Operation ForumTroll uses a Chrome sandbox escape against Russian entities
During 2025, a campaign identified as Operation ForumTroll exploited a Chrome sandbox escape vulnerability to target Russian government entities. The activity was cited as one of the notable real-world exploitation cases tied to Chrome zero-days that year.
Related entities
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Sources
2 references tracked. Mallory keeps watching after this page renders.
Chrome Zero-Day Vulnerabilities Exploited in 2025 – A Comprehensive Analysis
cybersecuritynews.com
Open sourceGoogle Chrome Emergency Update: High-Severity Memory Corruption Flaws Fixed in WebGPU and V8
securityonline.info
Open sourceSee the full picture, correlated to your attack surface.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.


