TECHNOLOGY

Discovery Of A Zero-day Vulnerability In Chrome, Already Actively Exploited

Google has released Chrome version 89.0.4389.72 containing the patch for a severe zero-day vulnerability already actively used in the wild. It is, therefore, essential to update the browser immediately.

On the occasion of the release of the latest Chrome, 89.0.4389.72, Google corrected a dangerous zero-day vulnerability already actively exploited in some attacks (in total, the latest version of the browser fixes 47 security vulnerabilities reported by external researchers).

Google has not released further technical details on Chrome’s zero-day vulnerability at this time to allow most users to install fixes and take necessary countermeasures to prevent other threat actors from exploiting this zero-day.

It is only known that the vulnerability, reported on February 11 by researcher Alison Huffman of Microsoft Browser Vulnerability Research, has been identified as CVE-2021-21166 and classified with a danger index by Google itself.

A Zero-day Vulnerability in Chrome: Let’s Install the Patch right away

It is therefore essential to promptly update the version of Google Chrome installed on your computer.

The new desktop version 89.0.4389.72 of Chrome has been released in the Stable channel and is already being rolled out for all Windows, Mac, and Linux users.

This means that the browser will automatically check for the recent update’s availability and install it as soon as it is available.

Alternatively, it is possible to manually install the update to Chrome 89 by accessing the Settings menu and clicking first on Help and then on About Google Chrome: if the latest version of the browser is already available, installation will be proposed.

Chrome’s Second Zero-day Corrected this year

With this vulnerability, Google has already corrected two zero-days in Chrome since the beginning of the year.

On February 4, the company released a fix for a heap buffer overflow flaw (CVE-2021-21148, also actively exploited) in Chrome’s V8 JavaScript rendering engine.

Last year, Google had already taken steps to fix five other zero-day vulnerabilities actively exploited between October 20 and November 12, 2020.

This shows, once again, how important it is to keep the software installed on your machine up-to-date: the patching activity is complex, but if adequately adopted, especially in the business environment, it can bring benefits in economic and security terms.

techbuzzfeeds

Recent Posts

Virtual Tour: What It Is And How To Do It

The virtual tour has become an exciting reality for small and medium-sized businesses. Until a…

6 hours ago

Advertising Makes Its Story On Snapchat

At barely 26 years old, Evan Spiegel, the young prodigy founder of Snapchat, decided to…

4 weeks ago

Chatbots And Voice Bots: How Artificial Intelligence Is Transforming Call Centers

They answer customer calls with a voice that sounds human, giving contemplated data and not…

1 month ago

Serverless Reaches Technological Maturity

Serverless, this other way of designing and running applications in the Cloud, has gained maturity…

2 months ago

Artificial Intelligence’s Impact On Medicine And Psychology

Is Artificial Intelligence Facing An Epochal Revolution? Artificial intelligence can analyze a vast amount of…

2 months ago

Google Analytics 4: With Machine Learning, An Even More Granular And Dynamic Map Of Users’ Online Behavior

The transition from a logic of "observation" of behavior to one of evaluation of the…

2 months ago