CERT-In issues a warning for Google Chrome on desktop users: Know why

A new CERT-In advisory warns Chrome users on Windows, Mac, and Linux of a flaw that allows remote hackers to run malicious code

Chrome
Chrome(Photo: Reuters)
Aashish Kumar Shrivastava New Delhi
2 min read Last Updated : Aug 21 2025 | 4:06 PM IST
The Indian Computer Emergency Response Team (CERT-In) has issued a high-severity warning for people who use Google Chrome on desktops. CERT-In, in an advisory, warned users regarding a vulnerability in Chrome that can allow a remote user to execute arbitrary code on systems. CERT-In has issued a ‘High’ severity warning for this vulnerability.

Who is affected by this?

  • Users running Google Chrome versions prior to 139.0.7258.138/.139 for Windows and Mac.
  • Users running Google Chrome versions prior to 139.0.7258.138 for Linux.

What’s the alert about?

In simpler words, CERT-In’s advisory means that a hacker sitting remotely could trick Chrome into running harmful commands on your system. This means that if you visit a malicious website or open a crafted link, the attacker could gain control over parts of your computer, install malware, steal data, or crash your system.
 
This not only poses a risk for disruption in services but also brings the risk of your entire system getting compromised, where a hacker can exploit it to extract the information that they need.

How to protect yourself from this?

According to the advisory from CERT-In, there is only one possible way to keep protected against this vulnerability. CERT-In has asked affected users to install the latest Google Chrome update, as provided by the US technology giant.
In related news, earlier in July, CERT-In issued a high-severity advisory warning users of multiple vulnerabilities across Microsoft Windows, Office, Azure, SQL Server, and other products. The flaws could have let attackers gain elevated privileges, steal sensitive data, execute remote code, or bypass security protections, potentially leading to spoofing, system tampering, or denial-of-service attacks. CERT-In urged both individuals and enterprises to apply Microsoft’s latest security patches immediately, noting that while no active exploitation was reported, the risks remained significant if systems were left unpatched.
*Subscribe to Business Standard digital and get complimentary access to The New York Times

Smart Quarterly

₹900

3 Months

₹300/Month

SAVE 25%

Smart Essential

₹2,700

1 Year

₹225/Month

SAVE 46%
*Complimentary New York Times access for the 2nd year will be given after 12 months

Super Saver

₹3,900

2 Years

₹162/Month

Subscribe

Renews automatically, cancel anytime

Here’s what’s included in our digital subscription plans

Exclusive premium stories online

  • Over 30 premium stories daily, handpicked by our editors

Complimentary Access to The New York Times

  • News, Games, Cooking, Audio, Wirecutter & The Athletic

Business Standard Epaper

  • Digital replica of our daily newspaper — with options to read, save, and share

Curated Newsletters

  • Insights on markets, finance, politics, tech, and more delivered to your inbox

Market Analysis & Investment Insights

  • In-depth market analysis & insights with access to The Smart Investor

Archives

  • Repository of articles and publications dating back to 1997

Ad-free Reading

  • Uninterrupted reading experience with no advertisements

Seamless Access Across All Devices

  • Access Business Standard across devices — mobile, tablet, or PC, via web or app

More From This Section

Topics :cybersecurityCyberattacksGoogle Chrome

First Published: Aug 21 2025 | 4:06 PM IST

Next Story