Close Menu
Alpha Leaders
  • Home
  • News
  • Leadership
  • Entrepreneurs
  • Business
  • Living
  • Innovation
  • More
    • Money & Finance
    • Web Stories
    • Global
    • Press Release
What's On
Meet SLB: The  billion oil services giant poised to cash in on AI data centers and the post-Strait of Hormuz oil exploration boom

Meet SLB: The $70 billion oil services giant poised to cash in on AI data centers and the post-Strait of Hormuz oil exploration boom

1 August 2026
Digital Health Funding Is Booming, Especially For Wearables

Digital Health Funding Is Booming, Especially For Wearables

1 August 2026
The rise of ‘conspicuous waiting’: The economic theory behind Gen Z’s viral lines

The rise of ‘conspicuous waiting’: The economic theory behind Gen Z’s viral lines

1 August 2026
Facebook X (Twitter) Instagram
Facebook X (Twitter) Instagram
Alpha Leaders
newsletter
  • Home
  • News
  • Leadership
  • Entrepreneurs
  • Business
  • Living
  • Innovation
  • More
    • Money & Finance
    • Web Stories
    • Global
    • Press Release
Alpha Leaders
Home » Google Chrome Deadline—21 Days To Update Or Stop Using Browser
Innovation

Google Chrome Deadline—21 Days To Update Or Stop Using Browser

Press RoomBy Press Room18 May 20255 Mins Read
Facebook Twitter Copy Link Pinterest LinkedIn Tumblr Email WhatsApp
Google Chrome Deadline—21 Days To Update Or Stop Using Browser

Republished on May 18 with update now deployed to most users and warnings on the critical step all users must take to make sure their browsers are secure.

Google has warned that Chrome is open to attack, and has rushed out a fix for a vulnerability that enables a hacker to steal login credentials and bypass multi-factor authentication. It’s a critical issue, and it’s imperative it’s fixed immediately. The U.S. government has now mandated all federal staff to update by June 5. Whether you’re a home or enterprise user, you should do the same.

America’s cyber defense agency has told all federal agency staff to “apply mitigations per vendor instructions… or discontinue use of the product if mitigations are unavailable.” That means update inside the next 21 days or stop using your browser until you do.

CISA’s formal mandate only applies to federal employees, but its remit extends to all organizations, “to help [them]

better manage vulnerabilities and keep pace with threat activity.” Given the nature of this threat, users should act now. CISA issues plenty of such mandates, but given Chrome’s install base and that this threat is now in the public domain, it really is critical for you to follow suit.

Although the binding operational directive only applies to federal staff, CISA “strongly urges all organizations to reduce their exposure to cyberattacks by prioritizing timely remediation of Catalog vulnerabilities as part of their vulnerability management.”

As I warned yesterday, Google’s fix for CVE-2025-4664 came with a warning “of reports that an exploit exists in the wild.” This was flagged on X by @slonser_, after discovering that “a technique that’s probably not widely known in the community” enabled a query parameter takeover that could exploit sensitive data included in the string. “In OAuth flows, this might lead to an Account Takeover” if that query parameter is stolen.

This means stealing the text string from Chrome that includes security session credentials after you’ve logged into a service. It enables an attacker to replicate the secure session on their own device.

Per SC Media, “its inclusion in the KEV catalog indicates the attackers have attempted to misuse the flaw in the wild.” But it’s unclear whether the flagged exploit is the POC raised or there are actual attacks underway with bad actors having identified the vulnerability independently. It doesn’t matter now. This is in the public domain. We’re now in the period of maximum risk as attackers strike before browsers are patched.”

Cybersecurity News warns “the vulnerability stems from an incorrect handle provided under unspecified circumstances in Chrome’s Mojo Inter-Process Communication (IPC) layer, potentially leading to unauthorized code execution or sandbox escape. The vulnerability poses significant risks, including unauthorized data leakage across web origins… Given its classification as a zero-day flaw, it was exploited before Google released the patch, heightening the urgency for mitigation.”

Check your Chrome browser for the notification an update has been downloaded and you need to relaunch to ensure it installs. You’re looking for Chrome version 136.0.7103.113/.114. Do this as soon as you can — don’t let dozens of open tabs hold you back. With this vulnerability, it is imperative to patch now.

The same update warning also applies to Microsoft Edge. “This CVE was assigned by Chrome,” the Windows-maker has confirmed, but given “Microsoft Edge (Chromium-based) ingests Chromium,” that fix also “addresses this vulnerability.”

There’s a good explainer on this vulnerability now available courtesy of Cyber-AppSec on Medium. “This flaw affects Chrome’s Loader component and could allow attackers to steal sensitive data from other websites — all through a crafty little trick involving the Link header.” While “most browsers don’t pay much attention to Link headers on these kinds of requests,” Chrome does, which enables the attacker to trick the browser into sending your session security info included in a full URL to their own server.

That attack is now in the public domain. While Google’s warning advised this urgent update “will roll out over the coming days/weeks,” it should be available to you now — most users have it. It’s not surprising it has been deployed quickly, given the short space of time between the public disclosure and the update, and CISA’s update mandate. But automatically downloading the software is not enough. As the Chrome ecosystem is being warned (1,2), “all Chrome users must ‘relaunch’ their browser now.”

Why the need to relaunch? As Google explains, “normally updates happen in the background when you close and reopen your computer’s browser. But if you haven’t closed your browser in a while, you might see a pending update.

While Chrome “saves your opened tabs and windows and reopens them automatically when it restarts,” that’s not the case for Incognito tabs which “won’t reopen when Chrome restarts.” Google says “if you don’t want to restart straight away, select Not now,” which means “the update applies the next time that you restart Chrome. But given this is a fix for an active attack, that’s not recommended this time around.

change your browser Chrome Attack cisa warning google attack microsoft warning windows warning
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link

Related Articles

Digital Health Funding Is Booming, Especially For Wearables

Digital Health Funding Is Booming, Especially For Wearables

1 August 2026
Data. Data. Data. How Can Wearables Really Help Us?

Data. Data. Data. How Can Wearables Really Help Us?

1 August 2026
Your Employees Aren’t Resisting Change. Their Brains Are.

Your Employees Aren’t Resisting Change. Their Brains Are.

1 August 2026
Top Anti-Fraud Tech Helping Businesses Fight AI Fraud

Top Anti-Fraud Tech Helping Businesses Fight AI Fraud

1 August 2026
Vehicle Recalls Are Skyrocketing—Here’s Which Models And Issues Are Most Frequent

Vehicle Recalls Are Skyrocketing—Here’s Which Models And Issues Are Most Frequent

31 July 2026
Galaxy S27 Ultra Details, OnePlus 16 Specs, Pixel 11 Pricing

Galaxy S27 Ultra Details, OnePlus 16 Specs, Pixel 11 Pricing

31 July 2026
Don't Miss
Exclusive: DeFi platform Azura launches after raising .9 million from Initialized

Exclusive: DeFi platform Azura launches after raising $6.9 million from Initialized

By Press Room22 October 2024

Azura, a new platform for decentralized finance, launched on Tuesday after raising $6.9 million in…

Unwrap Christmas Sustainably: How To Handle Gifts You Don’t Want

Unwrap Christmas Sustainably: How To Handle Gifts You Don’t Want

27 December 2024
Sam Altman’s World Wants To Scan Your Eyes To Prove You’re Human

Sam Altman’s World Wants To Scan Your Eyes To Prove You’re Human

22 October 2024
Stay In Touch
  • Facebook
  • Twitter
  • Pinterest
  • Instagram
  • YouTube
  • Vimeo
Latest Articles
Warsh considering reducing number of Fed meetings, NYT reports

Warsh considering reducing number of Fed meetings, NYT reports

1 August 20261 Views
Your Employees Aren’t Resisting Change. Their Brains Are.

Your Employees Aren’t Resisting Change. Their Brains Are.

1 August 20262 Views
LinkedIn adds ‘AI slop’ button after blocking billions of automated comment attempts

LinkedIn adds ‘AI slop’ button after blocking billions of automated comment attempts

1 August 20261 Views
Top Anti-Fraud Tech Helping Businesses Fight AI Fraud

Top Anti-Fraud Tech Helping Businesses Fight AI Fraud

1 August 20261 Views

Recent Posts

  • Meet SLB: The $70 billion oil services giant poised to cash in on AI data centers and the post-Strait of Hormuz oil exploration boom
  • Digital Health Funding Is Booming, Especially For Wearables
  • The rise of ‘conspicuous waiting’: The economic theory behind Gen Z’s viral lines
  • Data. Data. Data. How Can Wearables Really Help Us?
  • Warsh considering reducing number of Fed meetings, NYT reports

Recent Comments

No comments to show.
About Us
About Us

Alpha Leaders is your one-stop website for the latest Entrepreneurs and Leaders news and updates, follow us now to get the news that matters to you.

Facebook X (Twitter) Pinterest YouTube WhatsApp
Our Picks
Meet SLB: The  billion oil services giant poised to cash in on AI data centers and the post-Strait of Hormuz oil exploration boom

Meet SLB: The $70 billion oil services giant poised to cash in on AI data centers and the post-Strait of Hormuz oil exploration boom

1 August 2026
Digital Health Funding Is Booming, Especially For Wearables

Digital Health Funding Is Booming, Especially For Wearables

1 August 2026
The rise of ‘conspicuous waiting’: The economic theory behind Gen Z’s viral lines

The rise of ‘conspicuous waiting’: The economic theory behind Gen Z’s viral lines

1 August 2026
Most Popular
Data. Data. Data. How Can Wearables Really Help Us?

Data. Data. Data. How Can Wearables Really Help Us?

1 August 20261 Views
Warsh considering reducing number of Fed meetings, NYT reports

Warsh considering reducing number of Fed meetings, NYT reports

1 August 20261 Views
Your Employees Aren’t Resisting Change. Their Brains Are.

Your Employees Aren’t Resisting Change. Their Brains Are.

1 August 20262 Views

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025
  • April 2025
  • March 2025
  • February 2025
  • January 2025
  • December 2024
  • November 2024
  • October 2024
  • September 2024
  • August 2024
  • July 2024
  • June 2024
  • May 2024
  • April 2024
  • March 2024
  • February 2024
  • January 2024
  • December 2023
  • March 2022
  • January 2021
  • March 2020
  • January 2020

Categories

  • Blog
  • Business
  • Entrepreneurs
  • Global
  • Innovation
  • Leadership
  • Living
  • Money & Finance
  • News
  • Press Release
© 2026 Alpha Leaders. All Rights Reserved.
  • Privacy Policy
  • Terms of use
  • Advertise
  • Contact

Type above and press Enter to search. Press Esc to cancel.