New Delhi, May 20 — The Indian Computer Emergency Response Team (CERT-In), operating under the Ministry of Electronics and Information Technology (MeitY), has issued a critical security advisory for Google Chrome users across Windows, macOS, and Linux platforms. The alert warns of multiple high-risk vulnerabilities in outdated Chrome versions, potentially enabling cybercriminals to remotely control systems and steal sensitive information.

Affected Versions and Vulnerabilities
According to CERT-In, the vulnerabilities affect:
-
Linux systems running Chrome versions prior to 136.0.7103.113
-
Windows and macOS systems running versions prior to 136.0.7103.113 or 136.0.7103.114
These flaws originate from weaknesses in Chrome’s Loader and Mojo components:
-
The Loader is flagged for insufficient policy enforcement, a loophole that can allow unauthorised actions.
-
Mojo, a key system for inter-process communication, suffers from improper input validation, which could be exploited to execute arbitrary code.
Real-World Attacks Underway
What makes the warning even more pressing is that one of the vulnerabilities, CVE-2025-4664, is already being exploited in the wild. Cybercriminals are reportedly using malicious websites and phishing links to trick users into unknowingly launching malware or granting backdoor access to their systems. Successful exploitation could result in data theft, system crashes, or full system compromise.
Google’s Response and Fix
Google has confirmed the existence of these vulnerabilities and has already released patches. The security fixes are included in the latest Chrome Stable versions:
-
136.0.7103.113 for Linux
-
136.0.7103.113 or 136.0.7103.114 for Windows and macOS
Users must immediately update their browsers to the latest version to prevent exploitation.
How to Update Google Chrome
Updating Chrome is simple:
-
Open Chrome on your desktop.
-
Click the three-dot menu in the top-right corner.
-
Navigate to Help > About Google Chrome.
-
Chrome will automatically check for updates and install them.
-
Restart the browser to complete the process.
CERT-In’s Recommendation
CERT-In has urged all individuals and enterprises using Chrome to verify their browser version and apply updates without delay. “These vulnerabilities, if not patched, can be used by threat actors to gain control of devices and carry out targeted attacks,” the agency noted in its advisory.
Final Thoughts
As cyber threats become increasingly sophisticated, ensuring that browsers and software are up-to-date is one of the simplest yet most effective ways to protect against data breaches and malicious attacks. With CVE-2025-4664 already being exploited, the time to act is now.
Bhupendra Singh Chundawat is a seasoned technology journalist with over 22 years of experience in the media industry. He specializes in covering the global technology landscape, with a deep focus on manufacturing trends and the geopolitical impact on tech companies. Currently serving as the Editor at Udaipur Kiran, his insights are shaped by decades of hands-on reporting and editorial leadership in the fast-evolving world of technology.

