Security researchers have confirmed two actively exploited 0-day vulnerabilities, one in CrowdStrike Falcon and another in Google Chrome (CVE-2025-4917), that bypass existing defenses and allow remote code execution. For Indian SMBs running unpatched endpoints, the window to act is measured in hours, not days, as exploit chains are already circulating in the wild.
- Core Update: CrowdStrike Falcon sensor flaw (privilege escalation) plus Chrome V8 engine bug, both flagged as exploited in attacks on South Asian targets.
- Key Metrics / Specs: Chrome patch (v126.0.6478.126) ships with a critical severity rating; CrowdStrike's fix requires an immediate sensor update, no reboot needed.
- Access & Availability: Patches are live on Chrome auto-update and CrowdStrike's Falcon console. Enable auto-update for browsers and push the Falcon hotfix to all endpoints immediately.
Indian SMBs running legacy Windows 10 machines or older browser versions are the prime targets. Attackers are using phishing lures that invoke the Chrome flaw to drop ransomware, then abusing the CrowdStrike weakness to stay undetected. If your IT stack relies on manual patch cycles, prioritize this one over routine updates, the CISA advisory explicitly lists both CVEs under "Known Exploited Vulnerabilities."