HomeCyber BalkansChrome Zero-Day Vulnerability Detected as Actively Exploited

Chrome Zero-Day Vulnerability Detected as Actively Exploited

Published on

spot_img

A recent security update has been released for Google Chrome’s Stable and Extended stable channels. The update, version 116.0.5845.187, is available for Mac and Linux, while Windows users have the option of versions 116.0.5845.187 or 116.0.5845.188. The primary focus of this update is to address a critical vulnerability in the WebP format.

The vulnerability, known as CVE-2023-4863, is a heap buffer overflow and has been labeled as “Critical” by Google. This flaw was first reported by the Citizen Lab at the Munk School at the University of Toronto and Apple Security Engineering and Architecture (SEAR) on September 6. Google has stated that there is an exploit for this vulnerability already circulating in the wild.

In response to this security warning, Google has taken steps to address the vulnerability and release a patch. However, detailed information about the exploits and their potential impact has not been disclosed by Google at this time. The company has stated that access to bug details and links may be limited until most users have been informed about the fix. These restrictions are put in place to ensure the safety and security of their projects and users.

Google emphasizes the importance of applying this update promptly to prevent any potential harm or damage resulting from the exploitation of this vulnerability. Users are advised to follow these steps to update their Google Chrome browser:

1. Open Chrome on your computer.
2. Click on the “More” button at the top right corner of the browser.
3. Select “Help” followed by “About Google Chrome.”
4. Click on “Update Google Chrome.” If you don’t see this option, it means you are already on the latest version.
5. After updating, click on “Relaunch” to apply the changes.

It is crucial for users to implement this update as soon as possible to ensure the security and stability of their systems and browsers. By keeping their Google Chrome browser up to date, users can mitigate the risk and exposure to potential security threats.

In conclusion, the recent security update for Google Chrome aims to address a critical vulnerability in the WebP format. This update, labeled as version 116.0.5845.187 for Mac and Linux and 116.0.5845.187/.188 for Windows, is essential for users to prevent any potential harm resulting from the exploitation of this vulnerability. Users are advised to update their Google Chrome browser promptly by following the provided steps. By staying informed about the latest security updates and taking necessary precautions, users can enhance the security and protection of their online browsing experience.

Source link

Latest articles

MuddyWater Launches RustyWater RAT via Spear-Phishing Across Middle East Sectors

 The Iranian threat actor known as MuddyWater has been attributed to a spear-phishing campaign targeting...

Meta denies viral claims about data breach affecting 17.5 million Instagram users, but change your password anyway

 Millions of Instagram users panicked over sudden password reset emails and claims that...

E-commerce platform breach exposes nearly 34 million customers’ data

 South Korea's largest online retailer, Coupang, has apologised for a massive data breach...

Fortinet Warns of Active Exploitation of FortiOS SSL VPN 2FA Bypass Vulnerability

 Fortinet on Wednesday said it observed "recent abuse" of a five-year-old security flaw in FortiOS...

More like this

MuddyWater Launches RustyWater RAT via Spear-Phishing Across Middle East Sectors

 The Iranian threat actor known as MuddyWater has been attributed to a spear-phishing campaign targeting...

Meta denies viral claims about data breach affecting 17.5 million Instagram users, but change your password anyway

 Millions of Instagram users panicked over sudden password reset emails and claims that...

E-commerce platform breach exposes nearly 34 million customers’ data

 South Korea's largest online retailer, Coupang, has apologised for a massive data breach...