Close Menu
Alpha Leaders
  • Home
  • News
  • Leadership
  • Entrepreneurs
  • Business
  • Living
  • Innovation
  • More
    • Money & Finance
    • Web Stories
    • Global
    • Press Release
What's On
Millions Of Samsung Galaxy Phones Are In Line For A Free Upgrade

Millions Of Samsung Galaxy Phones Are In Line For A Free Upgrade

10 June 2026
Digital sovereignty isn’t the same thing as digital isolation. Asia’s governments should be careful

Digital sovereignty isn’t the same thing as digital isolation. Asia’s governments should be careful

10 June 2026
Apple iOS 27 Release Creates A Price Problem For iPhone 15 Owners

Apple iOS 27 Release Creates A Price Problem For iPhone 15 Owners

10 June 2026
Facebook X (Twitter) Instagram
Facebook X (Twitter) Instagram
Alpha Leaders
newsletter
  • Home
  • News
  • Leadership
  • Entrepreneurs
  • Business
  • Living
  • Innovation
  • More
    • Money & Finance
    • Web Stories
    • Global
    • Press Release
Alpha Leaders
Home » Google Chrome Deadline—21 Days To Update Or Stop Using Browser
Innovation

Google Chrome Deadline—21 Days To Update Or Stop Using Browser

Press RoomBy Press Room18 May 20255 Mins Read
Facebook Twitter Copy Link Pinterest LinkedIn Tumblr Email WhatsApp
Google Chrome Deadline—21 Days To Update Or Stop Using Browser

Republished on May 18 with update now deployed to most users and warnings on the critical step all users must take to make sure their browsers are secure.

Google has warned that Chrome is open to attack, and has rushed out a fix for a vulnerability that enables a hacker to steal login credentials and bypass multi-factor authentication. It’s a critical issue, and it’s imperative it’s fixed immediately. The U.S. government has now mandated all federal staff to update by June 5. Whether you’re a home or enterprise user, you should do the same.

America’s cyber defense agency has told all federal agency staff to “apply mitigations per vendor instructions… or discontinue use of the product if mitigations are unavailable.” That means update inside the next 21 days or stop using your browser until you do.

CISA’s formal mandate only applies to federal employees, but its remit extends to all organizations, “to help [them]

better manage vulnerabilities and keep pace with threat activity.” Given the nature of this threat, users should act now. CISA issues plenty of such mandates, but given Chrome’s install base and that this threat is now in the public domain, it really is critical for you to follow suit.

Although the binding operational directive only applies to federal staff, CISA “strongly urges all organizations to reduce their exposure to cyberattacks by prioritizing timely remediation of Catalog vulnerabilities as part of their vulnerability management.”

As I warned yesterday, Google’s fix for CVE-2025-4664 came with a warning “of reports that an exploit exists in the wild.” This was flagged on X by @slonser_, after discovering that “a technique that’s probably not widely known in the community” enabled a query parameter takeover that could exploit sensitive data included in the string. “In OAuth flows, this might lead to an Account Takeover” if that query parameter is stolen.

This means stealing the text string from Chrome that includes security session credentials after you’ve logged into a service. It enables an attacker to replicate the secure session on their own device.

Per SC Media, “its inclusion in the KEV catalog indicates the attackers have attempted to misuse the flaw in the wild.” But it’s unclear whether the flagged exploit is the POC raised or there are actual attacks underway with bad actors having identified the vulnerability independently. It doesn’t matter now. This is in the public domain. We’re now in the period of maximum risk as attackers strike before browsers are patched.”

Cybersecurity News warns “the vulnerability stems from an incorrect handle provided under unspecified circumstances in Chrome’s Mojo Inter-Process Communication (IPC) layer, potentially leading to unauthorized code execution or sandbox escape. The vulnerability poses significant risks, including unauthorized data leakage across web origins… Given its classification as a zero-day flaw, it was exploited before Google released the patch, heightening the urgency for mitigation.”

Check your Chrome browser for the notification an update has been downloaded and you need to relaunch to ensure it installs. You’re looking for Chrome version 136.0.7103.113/.114. Do this as soon as you can — don’t let dozens of open tabs hold you back. With this vulnerability, it is imperative to patch now.

The same update warning also applies to Microsoft Edge. “This CVE was assigned by Chrome,” the Windows-maker has confirmed, but given “Microsoft Edge (Chromium-based) ingests Chromium,” that fix also “addresses this vulnerability.”

There’s a good explainer on this vulnerability now available courtesy of Cyber-AppSec on Medium. “This flaw affects Chrome’s Loader component and could allow attackers to steal sensitive data from other websites — all through a crafty little trick involving the Link header.” While “most browsers don’t pay much attention to Link headers on these kinds of requests,” Chrome does, which enables the attacker to trick the browser into sending your session security info included in a full URL to their own server.

That attack is now in the public domain. While Google’s warning advised this urgent update “will roll out over the coming days/weeks,” it should be available to you now — most users have it. It’s not surprising it has been deployed quickly, given the short space of time between the public disclosure and the update, and CISA’s update mandate. But automatically downloading the software is not enough. As the Chrome ecosystem is being warned (1,2), “all Chrome users must ‘relaunch’ their browser now.”

Why the need to relaunch? As Google explains, “normally updates happen in the background when you close and reopen your computer’s browser. But if you haven’t closed your browser in a while, you might see a pending update.

While Chrome “saves your opened tabs and windows and reopens them automatically when it restarts,” that’s not the case for Incognito tabs which “won’t reopen when Chrome restarts.” Google says “if you don’t want to restart straight away, select Not now,” which means “the update applies the next time that you restart Chrome. But given this is a fix for an active attack, that’s not recommended this time around.

change your browser Chrome Attack cisa warning google attack microsoft warning windows warning
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link

Related Articles

Millions Of Samsung Galaxy Phones Are In Line For A Free Upgrade

Millions Of Samsung Galaxy Phones Are In Line For A Free Upgrade

10 June 2026
Apple iOS 27 Release Creates A Price Problem For iPhone 15 Owners

Apple iOS 27 Release Creates A Price Problem For iPhone 15 Owners

10 June 2026
Answers Explained For Thursday, June 11 (#1,096)

Answers Explained For Thursday, June 11 (#1,096)

10 June 2026
Why Selling Your SpaceX Shares Too Quickly Could Cost You

Why Selling Your SpaceX Shares Too Quickly Could Cost You

10 June 2026
Never Mind Foldable Phones —Logitech Has Launched A Folding Mouse

Never Mind Foldable Phones —Logitech Has Launched A Folding Mouse

10 June 2026
SpaceX’s Healthcare Plays

SpaceX’s Healthcare Plays

10 June 2026
Don't Miss
Unwrap Christmas Sustainably: How To Handle Gifts You Don’t Want

Unwrap Christmas Sustainably: How To Handle Gifts You Don’t Want

By Press Room27 December 2024

Every year, millions of people unwrap Christmas gifts that they do not love, need, or…

Exclusive: DeFi platform Azura launches after raising .9 million from Initialized

Exclusive: DeFi platform Azura launches after raising $6.9 million from Initialized

22 October 2024
Sam Altman’s World Wants To Scan Your Eyes To Prove You’re Human

Sam Altman’s World Wants To Scan Your Eyes To Prove You’re Human

22 October 2024
Stay In Touch
  • Facebook
  • Twitter
  • Pinterest
  • Instagram
  • YouTube
  • Vimeo
Latest Articles
Answers Explained For Thursday, June 11 (#1,096)

Answers Explained For Thursday, June 11 (#1,096)

10 June 20261 Views
Analysts were wrong about sky-high oil prices, and they have China to thank for it

Analysts were wrong about sky-high oil prices, and they have China to thank for it

10 June 20262 Views
Why Selling Your SpaceX Shares Too Quickly Could Cost You

Why Selling Your SpaceX Shares Too Quickly Could Cost You

10 June 20262 Views
Honda recalls nearly 900,000 cars thanks to rear suspension problems

Honda recalls nearly 900,000 cars thanks to rear suspension problems

10 June 20261 Views

Recent Posts

  • Millions Of Samsung Galaxy Phones Are In Line For A Free Upgrade
  • Digital sovereignty isn’t the same thing as digital isolation. Asia’s governments should be careful
  • Apple iOS 27 Release Creates A Price Problem For iPhone 15 Owners
  • How the World Cup is a high-stakes stage for Big Tech’s AI push
  • Answers Explained For Thursday, June 11 (#1,096)

Recent Comments

No comments to show.
About Us
About Us

Alpha Leaders is your one-stop website for the latest Entrepreneurs and Leaders news and updates, follow us now to get the news that matters to you.

Facebook X (Twitter) Pinterest YouTube WhatsApp
Our Picks
Millions Of Samsung Galaxy Phones Are In Line For A Free Upgrade

Millions Of Samsung Galaxy Phones Are In Line For A Free Upgrade

10 June 2026
Digital sovereignty isn’t the same thing as digital isolation. Asia’s governments should be careful

Digital sovereignty isn’t the same thing as digital isolation. Asia’s governments should be careful

10 June 2026
Apple iOS 27 Release Creates A Price Problem For iPhone 15 Owners

Apple iOS 27 Release Creates A Price Problem For iPhone 15 Owners

10 June 2026
Most Popular
How the World Cup is a high-stakes stage for Big Tech’s AI push

How the World Cup is a high-stakes stage for Big Tech’s AI push

10 June 20261 Views
Answers Explained For Thursday, June 11 (#1,096)

Answers Explained For Thursday, June 11 (#1,096)

10 June 20261 Views
Analysts were wrong about sky-high oil prices, and they have China to thank for it

Analysts were wrong about sky-high oil prices, and they have China to thank for it

10 June 20262 Views

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025
  • April 2025
  • March 2025
  • February 2025
  • January 2025
  • December 2024
  • November 2024
  • October 2024
  • September 2024
  • August 2024
  • July 2024
  • June 2024
  • May 2024
  • April 2024
  • March 2024
  • February 2024
  • January 2024
  • December 2023
  • March 2022
  • January 2021
  • March 2020
  • January 2020

Categories

  • Blog
  • Business
  • Entrepreneurs
  • Global
  • Innovation
  • Leadership
  • Living
  • Money & Finance
  • News
  • Press Release
© 2026 Alpha Leaders. All Rights Reserved.
  • Privacy Policy
  • Terms of use
  • Advertise
  • Contact

Type above and press Enter to search. Press Esc to cancel.