Google has fixed a zero-day vulnerability in Chrome, known as CVE-2025-5419, which is being actively exploited.
The vulnerability is an out-of-bounds read and write flaw in V8, the JavaScript engine used in Chrome and Node.js.
Users are urged to update to Chrome version 137.0.7151.68 immediately to patch the vulnerability on Windows, macOS, and Linux.
Although Chrome usually updates automatically, users can check for updates manually by navigating to the Chrome menu > Help > About Google Chrome and clicking 'Relaunch.'