Security News > 2022 > July > Google updates Chrome to squash actively exploited WebRTC Zero Day

Google has issued an unexpected update to its Chrome browser to address a zero-day WebRTC flaw that is actively being exploited.
The fix is installing Chrome 103.0.5060.114 for Windows and Chrome 103.0.5060.71 for Android, both of which will appear soon.
Google says the flaw is under active attack, but offers no insight into how one might detect it or defend against it other than by updating Chrome.
The release of new Chrome cuts is the fourth time in 2022 that Google has needed to issue emergency fixes.
Thankfully, Chrome updates itself with little user intervention required, so the software's many millions of users should be protected from these latest issues in short order.
The WebRTC flaw was reported on July 1 and Google's notification of updated Chrome cuts to fix it is dated July 4, suggesting folks on the Chrome team lost a weekend preparing the fix and did so with decent speed.
News URL
https://go.theregister.com/feed/www.theregister.com/2022/07/05/chrome_webrtc_zero_day/
Related news
- Google fixes Chrome zero-day exploited in espionage campaign (source)
- Google fixes exploited Chrome sandbox bypass zero-day (CVE-2025-2783) (source)
- Zero-Day Alert: Google Releases Chrome Patch for Exploit Used in Russian Espionage Attacks (source)
- Mozilla Patches Critical Firefox Bug Similar to Chrome’s Recent Zero-Day Vulnerability (source)
- After Chrome patches zero-day used to target Russians, Firefox splats similar bug (source)
- Google fixes Android zero-days exploited in attacks, 60 other flaws (source)
- Google Drops Cookie Prompt in Chrome, Adds IP Protection to Incognito (source)
- Google: 97 zero-days exploited in 2024, over 50% in spyware attacks (source)
- Google Reports 75 Zero-Days Exploited in 2024 — 44% Targeted Enterprise Security Products (source)