Google has issued a critical security update for Chrome on macOS, Windows, and Linux that fixes a zero-day vulnerability in the browser. On Tuesday, Google in a Chrome stable channel
Google has issued a critical security update for Chrome on macOS, Windows, and Linux that fixes a zero-day vulnerability in the browser. On Tuesday, Google in a Chrome stable channel update said it "is aware that an exploit for CVE-2023-6345 exists in the wild."


Google has not provided further details about the CVE-2023-6345 exploit, which was discovered last week by security researchers in Google's Threat Analysis Group (TAG). However, it is believed to be related to Skia, the open-source 2D graphics library in the Chrome graphics engine.

According to the notes for the macOS update 119.0.6045.199, the exploit allowed at least one attacker to "potentially perform a sandbox escape via a malicious file," which could theoretically result in arbitrary code execution and data theft.

Users who have Chrome browser set up to automatically update should not need to do anything. Anyone else is advised to manually update immediately (version 119.0.6045.199 on macOS) to avoid the risk posed by the zero-day exploit. In Chrome settings, click the About Chrome tab, and click Update Google Chrome. If there is no option to update, you are already on the latest version.

(Via Android Central.)
Tag: Chrome

This article, "Latest Chrome Browser Update Fixes Critical Security Flaw" first appeared on MacRumors.com

Discuss this article in our forums

original link


You may also be interested in this

Apple will allow alternat…

Apple is opening up iOS to alternative browsers and browser engines; but only in the EU. (via Cult of Mac - Apple news, reviews and how-tos)

Google Adds ‘AI Mod…

Google is updating the Chrome app for the iPhone and the iPad with a dedicated "AI Mode" button that matches functionality found in the desktop version of Chrome. AI Mode

U.S. DoJ Wants Google to …

The United States Department of Justice wants Google to sell off its Chrome browser as part of an ongoing antitrust lawsuit, reports Bloomberg. Earlier this year, Google was found to

Apple TVs will have nativ…

Native VPN support is coming to tvOS 17 | Image: Chris Welch / The Verge Apple TVs will get native VPN app support in tvOS 17, according to an Apple

Arc browser brings MySpac…

Web browsers that aren’t Safari have long offered the ability to customize their look with themes. For example, the frame and buttons from Chrome and Firefox can look different with

The latest Firefox update…

Macworld Mozilla celebrated the Fourth of July with the release of Firefox 115.0, which includes a number of new features and security fixes. Of note is that this is the

The Mac’s slow descent in…

Macworld Welcome to our weekly Apple Breakfast column, which includes all the Apple news you missed last week in a handy bite-sized roundup. We call it Apple Breakfast because we

Beats Studio Buds+ now av…

Apple subsidiary Beats today announces Beats Studio Buds +, an incredible addition to the Studio Buds lineup delivering balanced sound and enhanced features for both iOS and Android users. Now
X

A whimsical homage to the days in black and white, celebrating the magic of Mac OS. Dress up your blog with retro, chunky-grade pixellated graphics to evoke some serious computer nostalgia. Supports a custom menu, custom header image, custom background, two footer widget areas, and a full-width page template. I updated Stuart Brown's 2011 masterpiece to meet the needs of the times, made it responsive , got dark mode, custom search widget and more.You can download it from tigaman.com, where you can also find more useful code snippets and plugins to get even more out of wordpress.