Security News > 2022 > March > Emergency Google Chrome update fixes zero-day used in attacks

Emergency Google Chrome update fixes zero-day used in attacks
2022-03-25 19:10

Google has released Chrome 99.0.4844.84 for Windows, Mac, and Linux users to address a high-severity zero-day bug exploited in the wild.

This update was available immediately when BleepingComputer checked for new updates by going into Chrome menu > Help > About Google Chrome.

Even though Google said it detected attacks exploiting this zero-day in the wild, the company did not share technical details or additional info regarding these incidents.

Google Chrome users should have enough time to upgrade Chrome and prevent exploitation attempts until the browser vendor releases more info.

With this update, Google addressed the second Chrome zero-day since the start of 2022, the other one patched last month.

The Google Threat Analysis Group revealed that North Korean-backed state hackers exploited the CVE-2022-0609 zero-day weeks before the February patch.


News URL

https://www.bleepingcomputer.com/news/security/emergency-google-chrome-update-fixes-zero-day-used-in-attacks/

Related Vulnerability

DATE CVE VULNERABILITY TITLE RISK
2022-04-05 CVE-2022-0609 Use After Free vulnerability in Google Chrome
Use after free in Animation in Google Chrome prior to 98.0.4758.102 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
network
low complexity
google CWE-416
8.8

Related vendor

VENDOR LAST 12M #/PRODUCTS LOW MEDIUM HIGH CRITICAL TOTAL VULNS
Google 141 996 4899 2857 1622 10374