Google has fixed the sixth Chrome zero-day vulnerability this year in an emergency security update released today to counter ongoing exploitation in attacks. The company acknowledged the existence of an exploit for the security flaw in a new security advisory published today. "Google is aware that an exploit for CVE-2023-6345 exists in the wild," the company said. The vulnerability is now addressed in the Stable Desktop channel, with patched versions rolling out globally to Windows users and Mac and Linux users. Although the advisory says the security update may take days or weeks to reach the entire user base, it was available immediately when BleepingComputer checked for updates earlier today. The web browser will check for new updates automatically and install them after the next launch for users who don't want to do it manually. This high-severity zero-day vulnerability stems from an integer overflow weakness within the Skia open-source 2D graphics library, posing risks ranging from crashes to the execution of arbitrary code. The bug was reported on Friday, November 24, by Benoît Sevens and Clément Lecigne, two security researchers with Google's Threat Analysis Group. Google TAG is known for uncovering zero-days, often exploited by state-sponsored hacking groups in spyware campaigns targeting high-profile individuals like journalists and opposition politicians. The company says that access to the zero-day's details might remain restricted until most users have updated their browser, with the limitation to be extended if the flaw also impacts used by third-party software that hasn't yet been patched. "Access to bug details and links may be kept restricted until a majority of users are updated with a fix. We will also retain restrictions if the bug exists in a third party library that other projects similarly depend on, but haven't yet fixed," the company said. This aims to reduce the likelihood of threat actors developing their own CVE-2023-6345 exploits, taking advantage of newly released technical information on the vulnerability. In September, Google fixed two other zero-days exploited in attacks, the fourth and fifth ones since the start of 2023. Update: Revised story and title to correctly tag the zero-day as the sixth one patched this year. Google Chrome now auto-upgrades to secure connections for all users. Google shares plans for blocking third-party cookies in Chrome. Google: Hackers exploited Zimbra zero-day in attacks on govt orgs. Microsoft: SysAid zero-day flaw exploited in Clop ransomware attacks. Google Chrome's new "IP Protection" will hide users' IP addresses.
This Cyber News was published on www.bleepingcomputer.com. Publication date: Thu, 30 Nov 2023 23:19:27 +0000