Security News > 2021 > June > New Chrome 0-Day Bug Under Active Attacks – Update Your Browser ASAP!

New Chrome 0-Day Bug Under Active Attacks – Update Your Browser ASAP!
2021-06-10 03:25

Attention readers, if you are using Google Chrome browser on your Windows, Mac, or Linux computers, you need to update it immediately to the latest version Google released earlier today.

The internet services company has rolled out an urgent update to the browser to address 14 newly discovered security issues, including a zero-day flaw that it says is being actively exploited in the wild.

Although the search giant's Chrome team issued a terse statement acknowledging "An exploit for CVE-2021-30551 exists in the wild," Shane Huntley, Director of Google's Threat Analysis Group, hinted that the vulnerability was leveraged by the same actor that abused CVE-2021-33742, an actively exploited remote code execution flaw in Windows MSHTML platform that was addressed by Microsoft as part of its Patch Tuesday update on June 8.

More technical details about the nature of the attacks are to be released in the coming weeks so as to allow a majority of the users to install the update and prevent other threat actors from creating exploits targeting the flaw.

With the latest fix, Google has addressed a total of seven zero-days in Chrome since the start of the year -.

Chrome users can update to the latest version by heading to Settings > Help > About Google Chrome to mitigate the risk associated with the flaw.


News URL

http://feedproxy.google.com/~r/TheHackersNews/~3/SQiAlMayhYg/new-chrome-0-day-bug-under-active.html

Related Vulnerability

DATE CVE VULNERABILITY TITLE RISK
2021-06-15 CVE-2021-30551 Type Confusion vulnerability in multiple products
Type confusion in V8 in Google Chrome prior to 91.0.4472.101 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
network
low complexity
google fedoraproject CWE-843
8.8
2021-06-08 CVE-2021-33742 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Microsoft products
Windows MSHTML Platform Remote Code Execution Vulnerability
network
high complexity
microsoft CWE-119
7.5