New Delhi: The Computer Emergency Response Team (CERT-In) has issued a critical-severity cybersecurity advisory warning Google Chrome desktop users about multiple newly discovered vulnerabilities.
These vulnerabilities could expose systems to serious cyber threats.
According to the government agency, the vulnerabilities may allow remote attackers to execute arbitrary code, gain unauthorized access to sensitive information, escalate privileges, or trigger Denial of Service (DoS) attacks. The flaws affect both organizations and individual users relying on Google Chrome for desktop browsing.
CERT-In highlighted that the vulnerabilities stem from multiple technical issues within Chrome, including:
- User-after-free vulnerabilities in WebRTC, GPU, QUIC, XR, and DOM
- Out-of-bounds read in GPU components
- Heap buffer overflow in WebRTC and Chromecast
- Type confusion in GFX
- Insufficient policy enforcement in Service Worker
- Inadequate validation of untrusted input in the Input
- Improper implementation of UI mechanisms
The agency warned that successful exploitation of these flaws could lead to:
- Remote code execution
- System compromise
- Service disruption
- Unauthorized disclosure of sensitive data
- Privilege escalation on targeted devices
Google has acknowledged the reported vulnerabilities and confirmed that fixes are currently in development. The company has also published a detailed log of the identified issues, with patches expected to roll out through upcoming Chrome updates in the coming days or weeks.
CERT-In has strongly advised all users and organisations to immediately install the latest Chrome updates once available and remain vigilant by keeping browsers updated regularly to reduce cybersecurity risks.
Also Read
Meta Launches Premium Subscription Plans for Facebook, Instagram, WhatsApp




































