Google releases yet another emergency Chrome security update

Following the release of version 100 of its browser, Google has released a new update for Chrome to fix a high-severity zero-day vulnerability that is being actively exploited in the wild.

According to a new security advisory put out by the search giant, the company is aware that an exploit exists for this high-severity vulnerability tracked as CVE-2022-1364. 

Share your thoughts on Cybersecurity and get a free copy of the Hacker's Manual 2022. Help us find how businesses are preparing for the post-Covid world and the implications of these activities on their cybersecurity plans. Enter your email at the end of this survey to get the bookazine, worth $10.99/£10.99.

The bug itself is a confusion weakness in the Chrome V8 JavaScript engine and while these types of vulnerabilities usually lead to browser crashes after reading or writing memory out of buffer bounds, cybercriminals can also exploit them to execute arbitrary code on vulnerable systems.

The vulnerability was discovered by ClĂ©ment Lecigne from Google’s Threat Analysis Group who immediately reported it to the Google Chrome team. Although Google has observed this zero-day actively being exploited in the wild, the company has been tight lipped regarding any attacks. In its security advisory, it said that details about the bug and links will be “kept restricted until a majority of users are updated with a fix”.

Google Chrome Manual Update

(Image credit: Google)

Manually updating Chrome is your bet bet

Google Chrome 100.0.4896.127 for Windows, Mac and Linux will roll out in the next few weeks as an update.

However, due to the high-severity of this vulnerability, security-conscious users can update Chrome immediately by going into the Chrome menu, heading to Help and clicking on About Google Chrome. Here, they’ll be able to manually install the update themselves as opposed to waiting for Google to roll it out.

For those that would rather wait though, Chrome will automatically check for new updates and install them the next time you close and relaunch the browser.

This is the third zero-day vulnerability that has been discovered and patched in Chrome this year.

Via BleepingComputer



Comments