Google releases major Chrome update fixing 400 flaws and patches exploited Android zero‑day
Google rolled out Chrome version 150.0.7871.46/47, addressing almost 400 security vulnerabilities, including 15 classified as critical. The company disclosed that all flaws were discovered internally or reported by external researchers, and none were known to be exploited in the wild.
In the same month, Google’s Android security bulletin fixed 124 issues, notably a zero‑day vulnerability (CVE‑2025‑48595) in the Android Framework that was already being exploited. The flaw, rated 8.4 CVSS, allowed privilege escalation to system level on Android 14‑16 devices. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) listed it as actively exploited, urging federal agencies to patch within three days. This marks the fourth Android zero‑day patched in six months, highlighting the ongoing risk of mobile exploitation.
Both updates underline the importance of timely patching for users and organizations, especially given Android fragmentation and BYOD practices that can delay the rollout of security fixes.