Google Chrome update fixes 6th exploited zero-day
Google has released a significant security update for its Chrome browser, addressing a dozen vulnerabilities, including a high-severity flaw that is actively being exploited by attackers. The update, version 152.0.7977.82.83 for Windows and macOS, and 152.0.7977.82 for Linux, aims to protect users from potential remote code execution and other malicious activities. The most critical vulnerability patched, tracked as CVE202685046, is described as a type confusion issue within Chrome's V8 JavaScript and WebAssembly engine. This flaw could allow a remote attacker to execute arbitrary code within the browser's sandbox by tricking a user into visiting a specially crafted HTML page. Google confirmed awareness of active exploitation of this vulnerability but withheld specific details about the attacks to allow users time to apply the fix. This marks the sixth actively exploited zero-day vulnerability Google has addressed in Chrome this year. The V8 engine, which processes JavaScript and enables interactive web content, is a frequent target for such attacks.