• Menu
  • Skip to main content
  • Skip to primary sidebar

The Cyber Security News

Latest Cyber Security News

Header Right

  • Latest News
  • Vulnerabilities
  • Cloud Services
Cyber Security News

Google fixes actively exploited Chrome zero-day

You are here: Home / General Cyber Security News / Google fixes actively exploited Chrome zero-day

Chrome logo in browser displayed on desktop screen

Shutterstock

Google has released an updated version of its Chrome web browser following reports of a zero-day vulnerability being exploited in the wild.

✔ Approved Seller by TheCyberSecurity.News From Our Partners
F Secure Safe 2021

Protect yourself against all threads using F-Seure. F-Seure is one of the first security companies which has never been backed up by any governments. It provides you with an award-winning security plus an optimum privacy.

Get F-Secure Safe with 65% discount from a bitdefender official seller SerialCart® (Limited Offer).

➤ Activate Your Coupon Code


Version 88.0.4324.150 for Windows, Mac and Linux contains only one patch which is aimed at a memory corruption bug in Chrome’s V8 JavaScript engine, known as CVE-2021-21148.

The vulnerability, marked as high risk, was reported on 24 January by security researcher Mattias Buelens, who is also a lead software architect on THEOplayer. 

Google Chrome technical program manager Srinivas Sista said that the tech giant is “aware of reports that an exploit for CVE-2021-21148 exists in the wild”. He didn’t provide any additional details about the zero-day vulnerability due to risk of further exploitation, noting that the majority of users hadn’t yet been updated with a fix.

However, ZDNet notes that the date on which Google says the bug was reported, January 24, is just two days after Google’s Threat Analysis Group reported a hacking campaign carried out by North Korean hackers against the cyber security community. It’s believed this campaign may have relied on zero-day exploits in Chrome and Internet Explorer.

Chrome version 88.0.4324.150 has begun to roll out to users across Windows, Mac and Linux systems. Users can check if their Chrome browser is up to date by following these steps: 

  • Open your Chrome browser and look the three vertical dots on the top right corner
  • If the dots are coloured, there is a pending update
    • Green means the update it less than two days old
    • Orange means the update is about four days old
    • Red means the update is a least a week old
  • If the dots are coloured, click them to open the menu
  • Click “Update Google Chrome”
  • Exit your Chrome browser and reopen it to complete the update.
  • Google was forced to deal with another Chrome zero-day vulnerability in October of last year, when its Project Zero security team discovered that hackers were exploiting the bug to attack Chrome users’ systems. 

    The vulnerability, a memory corruption bug in the FreeType font-rendering library, prompted the tech giant to release the Chrome OS 86.0.4240.112 update, which addressed the detected zero-day security flaw on Google Chromebooks. 


    Some parts of this article are sourced from:
    www.itpro.co.uk

    Previous Post: «Cyber Security News Government Security Supplier Suffers Double Breach

    Reader Interactions

    Leave a Reply Cancel reply

    Your email address will not be published. Required fields are marked *

    Primary Sidebar

    Recent Posts

    • Google fixes actively exploited Chrome zero-day
    • Google fixes actively exploited Chrome zero-day
    • Government Security Supplier Suffers Double Breach
    • How to choose networking software for your business
    • Critical Flaws Reported in Cisco VPN Routers for Businesses—Patch ASAP
    • New Chrome Browser 0-day Under Active Attack—Update Immediately!
    • ICS vulnerabilities up 25 percent in 2020
    • A people counter that didn’t add up and the dangers of the COVID IoT boom
    • How not to overshare when crafting social media posts, out-of-office messages
    • Android Devices Prone to Botnet’s DDoS Onslaught

    Copyright © TheCyberSecurity.News, All Rights Reserved.