Security News > 2023 > September > Google fixes another Chrome zero-day bug exploited in attacks

Google fixes another Chrome zero-day bug exploited in attacks
2023-09-11 19:46

Google released emergency security updates to fix the fourth Chrome zero-day vulnerability exploited in attacks since the start of the year.

This update was immediately available when BleepingComputer checked for new updates via the Chrome menu > Help > About Google Chrome.

On Thursday, Apple patched two zero-days tagged by Citizen Lab as being exploited in attacks as part of an exploit chain known as BLASTPASS to infect fully-patched iPhones with NSO Group's Pegasus mercenary spyware.

While Google said the CVE-2023-4863 zero-day has been exploited in the wild, the company has yet to share more details regarding these attacks.

"Access to bug details and links may be kept restricted until a majority of users are updated with a fix," Google said.

Google to fight hackers with weekly Chrome security updates.


News URL

https://www.bleepingcomputer.com/news/google/google-fixes-another-chrome-zero-day-bug-exploited-in-attacks/

Related Vulnerability

DATE CVE VULNERABILITY TITLE RISK
2023-09-12 CVE-2023-4863 Out-of-bounds Write vulnerability in multiple products
Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page.
8.8

Related vendor

VENDOR LAST 12M #/PRODUCTS LOW MEDIUM HIGH CRITICAL TOTAL VULNS
Google 141 996 4895 2855 1622 10368