Google Chrome patches yet another serious security vulnerability
Chrome’s latest update patches several security bugs
When you purchase through links on our site, we may earn an affiliate commission.Here’s how it works.
As it put out the latest stable build of the cross-platform Chromeweb browser,Googlenoted that the build bundles eight security fixes, including one that it was aware was being exploited in the wild.
Six of the patchedChromevulnerabilities have a High severity rating, and have been flagged by variouscybersecurityresearchers from around the world including its own Google Project Zero.
However the discovery of the zero-day vulnerability, tracked as CVE-2021-30563, is credited to an anonymous researcher and was originally reported earlier this week.
“Google is aware of reports that an exploit for CVE-2021-30563 exists in the wild,” Googlesaidin its terse acknowledgement of the exploit.
Update without delay
Described as a type confusion bug in Google’sopen sourceWebAssembly andJavaScriptengine, V8, Google didn’t share additional details about the vulnerability or how it was being exploited in the wild, and for good reason.
“Access to bug details and links may be kept restricted until a majority of users are updated with a fix,” observed Google as it urged users to update to the latest release.
Reporting on the patched security issues,BleepingComputernotesthat CVE-2021-30563 brings the total number ofpatched zero-day vulnerabilitiesin Google’s web browser in 2021, to eight.
Are you a pro? Subscribe to our newsletter
Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!
Whileunraveling four zero-day flawsin popular web browsers, members of Google’s Threat Analysis Group (TAG), recently observed that some of them were developed by a commercial surveillance company, which then sold them to different government-backed actors.
Meanwhile, the new Chrome release has begun rolling out in Chrome’s Stable channel and will become available to all users over the following days.
With almost two decades of writing and reporting on Linux, Mayank Sharma would like everyone to think he’sTechRadar Pro’sexpert on the topic. Of course, he’s just as interested in other computing topics, particularly cybersecurity, cloud, containers, and coding.
7 myths about email security everyone should stop believing
Best Usenet client of 2024
This new malware utilizes a rare programming language to evade traditional detection methods