Chrome patched this error but cisa says it is still actively exploited


  • Google patched a new chrome error recently
  • Now cisa added the vulnerability to Kev that signaled abuse in nature
  • Federal agencies have three weeks to update Chrome

The US Cyber ​​Security and Infrastructure Security Agency (CISA) added a new Chrome Bug to its known utilized vulnerabilities (KEV) catalog, signaling abuse in nature, and gave the Federal Civil Civil Executive Branch (FCCEB) a deadline to patch things up.

The error is tracked as CVE-2025-4664. It was recently discovered by security researchers SolidLab and is described as an “insufficient policy enforcement in the Loader in Google Chrome”. At NVD, it was explained that the error allowed remote threat actors to leak transverse origin data via a designed HTML page.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top