Google has issued security updates for 230 vulnerabilities, including a Chrome zero-day that has already been exploited in attacks – the seventh such flaw fixed by the company since the start of the year.
The vulnerability, identified as CVE-2025-10585, affects Chrome’s V8 JavaScript engine and is described as a type-confusion bug. Google has rated it as high severity and warned that an exploit exists in the wild.
Details of the attacks have not been disclosed. Google typically restricts technical information about actively exploited vulnerabilities until most users have had an opportunity to install the relevant update.
The company has released patched versions of Chrome for Windows, macOS and Linux. Users can check for the update by opening Chrome’s settings, selecting “About Chrome” and restarting the browser when prompted.
Google’s security advisory credits a member of its Threat Analysis Group with reporting the flaw. The team investigates cyber attacks, including campaigns targeting Chrome users, but the company has not said who was behind the activity linked to this vulnerability.
The latest bug follows six other Chrome zero-days that Google has patched this year after they were found to have been used in attacks. Security researchers have repeatedly urged users to apply browser updates promptly because zero-days can be exploited before wider technical details become available.