Understanding CERT-In
India strengthens cybersecurity to combat AI-driven cyber attacks and enforce updated regulations across critical sectors.

Cybersecurity Alert in India: Urgent Updates for Google Chrome and Microsoft Edge Users Amid Growing Digital Threats

The Indian government has issued high-severity cybersecurity warnings for users of Google Chrome and Microsoft Edge, urging immediate action to update browsers and patch critical vulnerabilities. The alerts, published by the Indian Computer Emergency Response Team (CERT-In) under the Ministry of Electronics and Information Technology (MeitY), reflect the growing sophistication of cyber threats targeting India’s digital ecosystem.

These advisories come at a time when India’s IT and digital economy are expanding rapidly, making cybersecurity readiness a national priority.

🔐 Critical Cybersecurity Warnings: Chrome and Edge Vulnerabilities

⚙️ Google Chrome Security Flaws

According to CERT-In, multiple vulnerabilities have been detected in Google Chrome for Windows, macOS, and Linux. The most severe issues include heap buffer overflow and type confusion vulnerabilities, which can allow remote attackers to:

  • Execute arbitrary code on targeted systems
  • Steal or manipulate sensitive user data
  • Trigger denial-of-service (DoS) conditions
  • Gain complete remote control of affected devices

These vulnerabilities can be exploited simply by luring users to maliciously crafted web pages, making unpatched browsers particularly dangerous. Google has since rolled out security updates addressing these flaws in Chrome versions 130.0.6723.91 and above, and users are strongly advised to upgrade immediately.

🧩 Microsoft Edge “Use After Free” Exploit

Similarly, a “Use After Free” vulnerability was identified in Microsoft Edge’s Safe Browsing feature, a core component designed to detect phishing and malicious websites. This flaw could enable attackers to execute arbitrary code remotely or crash affected systems.
Microsoft has issued a patch for Edge Stable Channel version 130.0.2849.56, recommending users to enable automatic updates to avoid exploitation.

⚠️ Why These Updates Are Non-Negotiable

Outdated browsers are one of the most common entry points for cyber intrusions, ransomware infections, and credential theft. In the era of hybrid work and digital payments, even a single compromised browser can give cybercriminals access to enterprise networks, banking sessions, and government systems.

Regular software updates act as the first line of defense against such attacks, ensuring users benefit from the latest security enhancements, bug fixes, and encryption protocols.

🧠 India’s Broader Cybersecurity Landscape

🏛️ CERT-In’s Expanding Role

Established in 2004, CERT-In serves as India’s national agency for cyber incident response, threat intelligence, and vulnerability coordination. Over the past few years, its role has become increasingly vital, with rising threats such as phishing campaigns, ransomware, and state-sponsored cyberattacks targeting Indian infrastructure.

CERT-In’s alerts are part of a larger digital defense framework that includes:

  • Real-time threat monitoring across government and critical sectors
  • Collaborations with global security organizations like Google TAG, Microsoft Security Response Center (MSRC), and CISA (U.S.)
  • Capacity building initiatives to train cybersecurity professionals in both the public and private sectors

By publishing timely advisories, CERT-In empowers users, organizations, and developers to stay one step ahead of emerging threats.

🧩 Policy and Innovation Updates from MeitY

While cybersecurity remains a top concern, India is simultaneously moving forward with progressive IT policies and innovation-driven initiatives.

🏛️ Amendments to IT Rules, 2021

The draft amendments to the IT Rules (2021) focus on regulating synthetically generated information (deepfakes) and online gaming. MeitY is currently seeking stakeholder input to ensure a balanced framework that promotes innovation while curbing misuse. These amendments aim to:

  • Establish transparency obligations for AI-generated content
  • Strengthen user protection against harmful or deceptive media
  • Introduce responsible gaming guidelines for online platforms

💡 MeitY’s “2D Innovation Hub”

In line with India’s “Make AI Work for India” mission, MeitY has invited submissions for the 2D Innovation Hub, with the deadline set for November 22, 2025. The initiative seeks to fund projects in AI, digital inclusion, and sustainable tech, fostering collaboration between startups, academia, and government agencies.

This move underscores India’s commitment to becoming a global hub for responsible technology and cybersecurity innovation.

🌐 The Future of India’s Digital Security

India’s digital economy—projected to surpass $1 trillion by 2030—depends heavily on trust, safety, and resilience. Events such as the AI Conference in Uttar Pradesh and the National PSU Residential Summit 2025 are further reinforcing the connection between technology, governance, and economic growth.

The government’s emphasis on AI governance, data protection, and cyber hygiene education signals a holistic approach where security and innovation evolve together.

🚀 Final Takeaway

The recent cybersecurity warnings are a stark reminder that digital vigilance is everyone’s responsibility. Whether you’re an individual user, a small business, or a large enterprise, the steps are simple but powerful:

  1. Update your browsers immediately to the latest versions of Chrome and Edge.
  2. Enable automatic updates and avoid using unsupported software.
  3. Stay informed through official advisories from CERT-In and MeitY.
  4. Adopt best practices like using multi-factor authentication and secure passwords.

India’s cybersecurity readiness is not just about reacting to threats — it’s about building a safer, smarter digital future.

 

🔐 SEBI Cybersecurity Guidelines 2025: A Deep Dive into the New Framework

🌍 AI-Powered Cybersecurity: The Indian Perspective

 

2 Comments

Leave a Reply

Your email address will not be published. Required fields are marked *