Chrome Users Face High-Risk Vulnerabilities As India Sees 85% Rise In Cyber Attacks: What Users Need To Know| Special Report

Key Points
Bhubaneswar: If you use Google Chrome on a Windows PC, Mac or Linux computer, there is a reason to check your browser today.
The Indian Computer Emergency Response Team (CERT-In) has issued a high-severity vulnerability warning over five security flaws in Google Chrome for desktop. The vulnerabilities could potentially allow a remote attacker to execute arbitrary code on a targeted computer or cause a denial-of-service condition.
The warning comes against a backdrop of a sharp rise in cyber-security incidents being reported to and tracked by CERT-In in India.
According to data placed before the Lok Sabha by the Ministry of Electronics and Information Technology, the number of cyber-security incidents rose from 15,92,917 in 2023 to 20,41,360 in 2024 and 29,44,248 in 2025.
That means the number of tracked incidents increased by nearly 85% in just two years.
The Chrome warning, therefore, is not simply another technical software update. It arrives at a time when the country's cyber threat environment is expanding rapidly.
What exactly has CERT-In warned about?
CERT-In has flagged five vulnerabilities in Chrome:
- CVE-2026-19556 — Use-after-free vulnerability in V8
- CVE-2026-19557 — Use-after-free vulnerability in TabStrip
- CVE-2026-19558 — Use-after-free vulnerability in Extensions
- CVE-2026-19559 — Use-after-free vulnerability in HTML
- CVE-2026-19560 — Use-after-free vulnerability in Blink
The vulnerabilities affect Chrome versions prior to 151.0.7922.137/.138 for Windows and Mac and prior to 151.0.7922.137 for Linux, according to the CERT-In warning.
Google's corresponding Stable Channel release addresses the five flaws.
The technical term appearing repeatedly in the warning is “use-after-free.”
For an ordinary user, that essentially means a programming flaw involving computer memory. Under certain circumstances, an attacker could manipulate that flaw to make the browser perform operations it was not supposed to perform.
The more serious concern is the potential for remote code execution.
In plain English, a successful attack could potentially give an attacker the ability to make the targeted system execute malicious instructions.
Why the rising cyber-attack numbers make this more important
This is where the Chrome warning becomes relevant beyond the technical world.
India recorded 15.93 lakh cyber-security incidents in 2023. The number crossed 20 lakh in 2024, before jumping to 29.44 lakh in 2025.
The increase between 2024 and 2025 alone was more than 44%.
The government says CERT-In advises affected organisations on remedial measures and coordinates incident response with organisations, service providers, regulators and law-enforcement agencies.
In other words, cyber threats are no longer an occasional technical nuisance. They are becoming a persistent part of India's digital environment.
And the browser is one of the most exposed pieces of software on an ordinary computer.
Every day, users open dozens of webpages, click links, download files, access email, use banking services, log into government portals and operate social-media accounts through browsers.
That makes an unpatched browser an attractive target.
How can an ordinary Chrome user become vulnerable?
The worrying part is that the user may not need to knowingly download malware.
CERT-In says the Chrome vulnerabilities could be exploited by convincing a victim to open a specially crafted web request.
That could potentially involve a malicious webpage or a link delivered through a phishing message.
Some of the vulnerabilities are specifically associated with crafted HTML content, while the Extensions vulnerability involves convincing a user to install a malicious extension.
This is why the familiar cyber-security advice — “think before you click” — remains relevant.
A link that appears harmless may not be harmless.
How do you know whether your Chrome is vulnerable?
You do not need technical knowledge to find out.
Open Chrome and go to:
Three dots → Help → About Google Chrome
Chrome will display the installed version and automatically check for an update.
📱 Get Argus News App
✨If your browser is running an older version than the build specified by CERT-In, update it and restart Chrome.
The important point is this:
Do not wait for your computer to show symptoms before updating.
A browser can remain vulnerable without producing an obvious warning.
What signs should make you suspicious?
There is no single symptom that can prove these particular Chrome vulnerabilities have been exploited.
However, users should pay attention if unusual behaviour begins after visiting an unfamiliar or suspicious website.
Possible warning signs include:
- Chrome repeatedly crashing or becoming unusually unstable.
- Unexpected pop-ups or redirects.
- New browser extensions that the user did not knowingly install.
- Search-engine or browser settings changing without permission.
- Unknown tabs or webpages opening automatically.
- Unusual computer behaviour immediately after visiting a suspicious website.
- Security software suddenly reporting unusual browser activity.
These signs do not necessarily mean that a Chrome vulnerability has been exploited. They can have many other causes.
But they are reasons to investigate rather than ignore the problem.
The most important warning sign is actually your Chrome version
There is a subtle but important point here.
Users often ask: “How will I know if I have been hacked?”
For this particular warning, that is the wrong first question.
The first question should be:
“Am I running a vulnerable version of Chrome?”
If the answer is yes, update it.
CERT-In itself recommends applying the vendor's appropriate updates.
What should you do if you suspect compromise?
First, stop interacting with a suspicious webpage.
Update Chrome and restart the browser.
Then check the list of installed extensions and remove anything unfamiliar.
It is also sensible to update the operating system and other software on the computer, because browser security is only one part of the overall defence.
If suspicious behaviour continues, users should consider running the computer's available security checks and seeking technical assistance rather than continuing to use the machine for sensitive transactions.
Until the issue is resolved, avoid entering sensitive information such as banking credentials or passwords into webpages that appear suspicious.
India's cyber-security machinery is already responding
The government's response to the rising cyber threat is not limited to issuing individual vulnerability warnings.
The Lok Sabha reply says CERT-In is India's designated national agency for responding to cyber-security incidents under Section 70B of the Information Technology Act.
The government also has the National Cyber Coordination Centre, which monitors cyberspace for threats and shares threat intelligence with organisations and governments.
There is also the Cyber Swachhta Kendra, a citizen-centric CERT-In service that helps detect malicious programmes and provides free tools to remove them.
CERT-In also continuously issues alerts and advisories on emerging vulnerabilities and countermeasures.
But these systems can only do so much if users leave vulnerable software unpatched.
The bigger lesson for every internet user
The jump from 15.93 lakh cyber-security incidents in 2023 to 29.44 lakh in 2025 provides the bigger context to the Chrome warning.
It does not mean that every one of those incidents involved Chrome, nor does it mean every Chrome user is currently under attack.
But it does demonstrate the scale of the cyber-security environment in which ordinary users are operating.
And that makes a simple browser update more important than it may appear.
The safest escape route is not to wait for evidence that you have been hacked.
Check your Chrome version.
If it is outdated, update it, restart the browser and keep it updated going forward.
In an
environment where India's tracked cyber-security incidents have nearly doubled
in two years, leaving a known browser vulnerability unpatched is an unnecessary
risk.
Also Read: Narcotics Trade Changing Face in Odisha: Women Emerging Key Driver of Brown Sugar Trade in State| Special Report
Related Topics
Explore more stories