Threat Advisory

Google Chrome Hit by Second Zero-Day Attack - Urgent Patch Update Released

Threat: Vulnerability
Criticality: High
[subscribe_to_unlock_form]

Summary:

Google has published a security update for the Chrome web browser to address the second zero-day vulnerability discovered to be used in attacks this year. Google is aware that CVE-2023-2136 has a public exploit. The updated version, 112.0.5615.137, addresses eight vulnerabilities in all. According to Google, the Linux version will launch "soon," and is now only available for Windows and Mac users.[/subscribe_to_unlock_form]

Summary:

Google has published a security update for the Chrome web browser to address the second zero-day vulnerability discovered to be used in attacks this year. Google is aware that CVE-2023-2136 has a public exploit. The updated version, 112.0.5615.137, addresses eight vulnerabilities in all. According to Google, the Linux version will launch "soon," and is now only available for Windows and Mac users.[emaillocker id="1283"]

The open-source C++ 2D graphics package Skia, which is owned by Google, has a high-severity integer overflow vulnerability identified as CVE-2023-2136. Skia is seen as a crucial part of Chrome's rendering pipeline since it gives the browser a set of APIs for producing graphics, text, shapes, images, and animations. When an operation produces a value greater than the upper limit for a particular integer type, it is known as an integer overflow bug, which frequently results in unexpected program behavior or security concerns. According to Skia, this could result in improper rendering, memory corruption, and arbitrary code execution that grants unauthorized system access.

Advanced threat actors, who are frequently state-sponsored and target high-profile people working for the government, the media, or other crucial institutions, frequently take advantage of these flaws. Therefore, it is advised that all Chrome users install the latest version as soon as it becomes available.

Recommendations:

We strongly recommend you install the latest Google Chrome version 112.0.5615.137

References:

The following reports contain further technical details:

https://www.bleepingcomputer.com/news/security/google-patches-another-actively-exploited-chrome-zero-day/

[/emaillocker]
crossmenu