Emergency Google Chrome Update Fixes Zero-day Exploited In The Wild

Emergency Google Chrome Update Fixes Zero-day Exploited In The Wild

Google has released Chrome 94.0.4606.61 for Windows, Mac, and Linux, an emergency update addressing a high-severity zero-day vulnerability exploited in the wild.

“Google is aware that an exploit for CVE-2021-37973 exists in the wild,” the browser vendor revealed in today’s security advisory.

This Chrome update has started rolling out worldwide to the Stable desktop channel and will be available to all users over the following days and weeks.

The update was available immediately when BleepingComputer manually checked for new updates from Chrome menu > Help > About Google Chrome.

Also Read: 10 Government Data Leaks In Singapore: Prevent Cybersecurity

The web browser will also check for new updates and automatically update itself after the next launch.

Details regarding ongoing attacks not disclosed

The zero-day security flaw fixed today was reported the day the first Google Chrome 94 stable release was published, on September 21, by Clément Lecigne from Google TAG, with assistance from Sergei Glazunov and Mark Brand from Google Project Zero.

The bug, tracked as CVE-2021-37973, is a use after free weakness in Portals, Google’s new web page navigation system for Chrome.

Successful exploitation of this vulnerability can let attackers execute arbitrary code on computers running unpatched Chrome versions.

Even though Google said it detected in the wild attacks abusing CVE-2021-37973, the company did not share additional info regarding these incidents.

“Access to bug details and links may be kept restricted until a majority of users are updated with a fix,” Google said.

“We will also retain restrictions if the bug exists in a third party library that other projects similarly depend on, but haven’t yet fixed.”

Also Read: How To Anonymised The Data: What Are The Importance Of This?

Chrome users should have enough time to install the security update to prevent exploitation attempts until more info is available.

Eleventh zero-day fixed this year

With this bug, Google has patched 11 zero-day vulnerabilities in the Chrome web browser since the start of 2021.

The other Chrome zero-day bugs Google fixed this year are:

Because these security bugs are all known to have been abused by threat actors in the wild, installing all Google Chrome updates is strongly recommended as soon as they are available.

Privacy Ninja

Recent Posts

Enhancing Website Security: The Importance of Efficient Access Controls

Importance of Efficient Access Controls that every Organisation in Singapore should take note of. Enhancing…

3 weeks ago

Prioritizing Security Measures When Launching Webpage

Prioritizing Security Measures When Launching a Webpage That Every Organisation in Singapore should take note…

3 weeks ago

The Importance of Regularly Changing Passwords for Enhanced Online Security

Importance of Regularly Changing Passwords for Enhance Online Security that every Organisation in Singapore should…

4 weeks ago

Mitigating Human Errors in Organizations: A Comprehensive Approach to Data Protection and Operational Integrity

Comprehensive Approach to Data Protection and Operational Integrity that every Organsiation in Singapore should know…

4 weeks ago

The Importance of Pre-Launch Testing in IT Systems Implementation

Here's the importance of Pre-Launch Testing in IT Systems Implementation for Organisations in Singapore. The…

1 month ago

Understanding Liability in IT Vendor Relationships

Understanding Liability in IT Vendor Relationships that every Organisation in Singapore should look at. Understanding…

1 month ago