web analytics
Home » Technology » Google » Google Releases Chrome Emergency Update To Fix Vulnerability

Google Releases Chrome Emergency Update To Fix Vulnerability

There is a new emergency security update for Google Chrome. The new update is recommended for all users as it fixes a vulnerability that has been identified as high-risk and is actively being exploited.

Google has released Chrome version 107.0.5304.12X for Windows, Mac, and Linux. Google has also released an update for the extended version. This version is only regularly updated every eight weeks, but of course, it also gets emergency updates immediately.

According to the description, it is an emergency update that fixes a highly dangerous vulnerability that is already being actively exploited in the wild: “Google is aware that an exploit for CVE-2022-4135 exists in the wild,” it says see the newly published security advisory.

Update Chrome ASAP

The new versions are already being rolled out worldwide. If you use Chrome, you can also force the update by actively checking for updates via the browser settings (Chrome menu > Help > About Google Chrome > Updates). The web browser automatically checks for new updates and, if possible, installs them after the next start or indicates an available update.

The fixed zero-day bug is a serious vulnerability that exploits a heap buffer overflow in the graphics processor. It was reported by a Google security researcher. By reading or writing memory outside of the buffer bounds, attackers can also exploit the vulnerability to execute arbitrary code.

Details unknown

Since Google says it has already discovered active attacks on this vulnerability, no further technical details or additional information on the exploit will be published for the time being. “Access to error details and links will remain restricted until a majority of users have received an update,” reports Google. This is standard practice to avoid attracting free riders who want to exploit the vulnerability after it has been discovered.

“We will also keep limitations when the bug exists in a third-party library that other projects depend on in a similar way, but have not yet been fixed.” This includes the Microsoft Edge web browser.