Google patches Chrome zero-day under active exploitation, urges immediate update
Google rolls out Chrome 152 to fix 12 vulnerabilities, including a zero-day already exploited in attacks; update now.
The vulnerability is described as a type confusion issue in V8, Chrome's JavaScript engine, allowing a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. It was discovered by security researcher Salvatore Gulizia, who received a $1,000 reward as part of Google's bug bounty program.
Google plans a gradual rollout of the update, though most users should receive it automatically. Those unsure can check by opening the browser menu, selecting Help, and navigating to About Google Chrome to see the version number.
The patch addresses a total of 12 security flaws, most rated high severity. This is the sixth zero-day Google has fixed in Chrome since the start of the year. TechRadar notes that other Chromium-based browsers, including Microsoft Edge, Brave, Opera, and Vivaldi, are also affected, and users should apply the latest updates as soon as possible.
As is typical, Google has not disclosed full technical details of the exploit, likely to allow time for most browsers to be protected.