Google releases emergency fix to plug zero‑day hole in Chrome

Cyber Security

The emergency release comes a mere three days after Google’s previous update that plugged another 19 security loopholes

Google has released an emergency update for its Chrome web browser to fix a zero-day vulnerability that is known to be actively exploited in the wild by malicious actors. The security loophole affects the Windows, macOS, and Linux versions of the popular browser.

“Google is aware that an exploit for CVE-2021-37973 exists in the wild,” Google revealed about the newly disclosed zero-day vulnerability. The bug classified as high in severity is a use-after-free flaw in the Portals Web API, Google’s webpage navigation component of the Chromium browser engine

Clément Lecigne of Google’s Threat Analysis Group (TAG) was credited with the discovery of the vulnerability on September 21st, with technical assistance provided by two of his colleagues from Google Project Zero Sergei Glazunov and Mark Brand.

The vulnerability was so severe that it necessitated its own official update for the Chrome browser. The release is especially notable, considering that it was rolled out mere days after Google pushed out a stable version of Chrome that fixed another 19 bugs. It took Google’s team just three days to release a fix after they were notified by Lecigne and his colleagues about the flaw being actively exploited in the wild.

The United States’ Cybersecurity and Infrastructure Security Agency (CISA) also took note of the release and issued a security advisory urging both users and system administrators to update their browsers. “Google has released Chrome version 94.0.4606.61 for Windows, Mac, and Linux. This version addresses a vulnerability—CVE-2021-37973—that an attacker could exploit to take control of an affected system. An exploit for this vulnerability exists in the wild,” said the agency.

Considering the timing and severity of the disclosed vulnerability, you would do well to update your browser to the latest version (94.0.4606.61) as soon as possible. If you have automatic updates enabled, the browser should be able to update to the newest available version on its own.

However, if you haven’t enabled the function yet, you can also update your browser manually by visiting the About Google Chrome section, which can be found under Help in the menu bar.

Products You May Like

Articles You May Like

Cyberespionage the Gamaredon way: Analysis of toolset used to spy on Ukraine in 2022 and 2023
Data Breach at MC2 Data Leaves 100 Million at Risk of Fraud
AI-Powered Rhadamanthys Stealer Targets Crypto Wallets with Image Recognition
Why system resilience should mainly be the job of the OS, not just third-party applications
US Sanctions Crypto Exchanges for Facilitating Russian Cybercrime

Leave a Reply

Your email address will not be published. Required fields are marked *