Breaking news

Google Confirms Chrome Attack – What You Need To Do

Google has confirmed an active attack targeting Chrome users, with hackers leveraging generative AI models such as ChatGPT, Copilot, and DeepSeek to develop malware capable of extracting sensitive information, including login credentials and financial data.

The Growing Threat Landscape

Warnings about malicious email links are becoming increasingly frequent, as traditional security measures struggle to keep up with AI-driven threats. Despite these advances, cyberattacks still require user interaction—such as clicking a link—to be successful. The latest attack exploits a critical Chrome vulnerability, prompting Google to release an urgent update for Windows users.

“Google is aware of reports that an exploit (a piece of code, software, or technique that takes advantage of a vulnerability) for CVE-2025-2783 is being used in real-world attacks,” the company stated on Tuesday.

Update Your Browser Now

Chrome for Windows has been updated to version 134.0.6998.177/.178, which will roll out in the coming days or weeks. However, users can manually check for updates to install the fix immediately. Once downloaded, restarting the browser is crucial to apply the security patch.

What to Watch Out For

The attack was first identified by Kaspersky, which discovered a wave of infections caused by an unknown, highly sophisticated malware strain.

  • How the attack works: Victims receive a highly personalized phishing email containing a malicious link. Once clicked, Chrome opens, and the infection occurs instantly—without requiring any further action from the user.
  • Technical findings: Kaspersky’s researchers analyzed the exploit, reverse-engineered its logic, and reported the zero-day vulnerability to Google. The exploit bypassed Chrome’s security protections seamlessly, making it particularly concerning.

The Nature Of The Attack

According to Kaspersky, a logical error in the interface between Chrome’s sandbox and the Windows operating system was responsible for the vulnerability. As a result, this attack and the subsequent patch apply only to Windows users.

Kaspersky also suggests that the attack is likely espionage-driven, targeting media, educational institutions, and state organizations—primarily in Russia. The level of sophistication indicates the involvement of a state-sponsored hacking group.

“The exploit was designed to work alongside a second exploit that enables remote code execution. Unfortunately, we have not yet obtained this second exploit, as doing so would require waiting for another wave of attacks—putting users at risk,” Kaspersky reported.

Next Steps For Users

While Google has patched the first exploit, the second exploit remains a concern. The risk of further attacks persists, making user vigilance critical.

  • Update Chrome immediately to the latest version.
  • Avoid clicking on suspicious links—especially those in emails.
  • Enable automatic updates to ensure future security patches are installed promptly.

Final Thoughts

This security incident comes at a challenging time for Google, following Microsoft’s recent claim that Edge offers better protection than Chrome. However, Google’s swift response with an urgent update is commendable. Now, it is up to users to ensure they install the fix and stay cautious against emerging threats.

WhatsApp Introduces Parent-Supervised Accounts For Users Under 13

Enhanced Security And Messaging Control

WhatsApp has introduced a new type of account designed for users under the age of 13, allowing parents to supervise messaging activity. The accounts are limited to messaging and voice calls and do not include advertising features, reflecting growing demand from families for safer communication tools for younger users.

Streamlined Verification And Parental Oversight

Creating a supervised account requires a parent or guardian to complete a dual-device verification process using a QR code. This procedure links the child’s device with the parent’s account, allowing guardians to monitor certain activities. Once the connection is established, parents can receive notifications when their child adds, blocks or reports contacts. The system is designed to provide oversight while still allowing children to communicate with approved contacts.

Restricted Features With Full Encryption

Several WhatsApp functions are restricted within supervised accounts. Access to Meta AI, Channels and Status updates is disabled, and disappearing messages are not available in individual chats. Despite these limitations, conversations remain protected with WhatsApp’s end-to-end encryption, ensuring that messages and calls remain private between participants.

Controlled Interactions And Transition Options

Additional safety tools help pre-teens manage interactions with unfamiliar contacts. Context cards provide details about messages received from unknown users, including shared groups and the country where the account originated. Users also have the option to silence incoming calls from numbers that are not saved in their contacts.

Chat requests and invitations to join group conversations require a six-digit parental PIN before they can be accepted. As children grow older, WhatsApp will inform them about the option to convert their supervised profile into a standard account. Parents can postpone this transition for up to 12 months if they wish to maintain supervision for a longer period.

A Broader Commitment To Digital Safety

WhatsApp’s initiative builds on Meta’s longstanding efforts to enhance the safety of young users across its platforms, including Instagram and Facebook. With over 3 billion active users worldwide, WhatsApp is reinforcing its commitment to a secure digital environment. This move also coincides with regulatory trends in countries such as Denmark, Germany, Spain, and the U.K., where steps are being taken to restrict social media access for younger users.

The Future Forbes Realty Global Properties
Aretilaw firm
eCredo
Uol

Become a Speaker

Become a Speaker

Become a Partner

Subscribe for our weekly newsletter