Security News > 2022 > April > Google Chrome emergency update fixes zero-day used in attacks

Google Chrome emergency update fixes zero-day used in attacks
2022-04-14 21:36

Google has released Chrome 100.0.4896.127 for Windows, Mac, and Linux, to fix a high-severity zero-day vulnerability actively used by threat actors in attacks.

"Google is aware that an exploit for CVE-2022-1364 exists in the wild," Google said in a security advisory released today.

While Google states that this Chrome update will roll out in the next few weeks, users can receive it immediately by going into the Chrome menu > Help > About Google Chrome.

The browser will also automatically check for new updates and install them the next time you close and relaunch Google Chrome.

While Google said they have detected attacks exploiting this zero-day, it did not provide further details regarding how these attacks are conducted.

As this zero-day is known to be used in attacks, it is strongly advised to update Google Chrome as soon as possible.


News URL

https://www.bleepingcomputer.com/news/security/google-chrome-emergency-update-fixes-zero-day-used-in-attacks/

Related Vulnerability

DATE CVE VULNERABILITY TITLE RISK
2022-07-26 CVE-2022-1364 Type Confusion vulnerability in Google Chrome
Type confusion in V8 Turbofan in Google Chrome prior to 100.0.4896.127 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
network
low complexity
google CWE-843
8.8

Related vendor

VENDOR LAST 12M #/PRODUCTS LOW MEDIUM HIGH CRITICAL TOTAL VULNS
Google 102 253 4216 4506 727 9702