Skip to main content

A zero-day Google Chrome security flaw requires you to update now

Google released an update to its Chrome browser for Windows and Mac users, and the internet giant strongly recommends that users apply the update as soon as possible. The update contains 14 security fixes — including a zero-day security flaw — that if left unchecked would leave the system vulnerable to attacks. Google categorized these fixes as critical, high, and medium importance.

Windows and Mac users who also surf the internet with the Chrome browser will want to make sure that they’re on version 91.0.4472.101. To make sure that you’re on the latest build of Chrome, launch your browser and then click on the three dots stacked vertically at the top right. Navigate to Settings, and then click About Chrome. From there, you’ll be able to view the Chrome version number, and you can update the browser if it wasn’t automatically updated in the background.

If you don’t immediately update your browser, Google should be pushing out the update to users in the coming days or weeks, the company stated on its blog.

One of the security vulnerabilities that was listed — CVE-2021-30551 — is related to a flaw in Windows 10 that Microsoft had recently patched with its newest OS update.

“Chrome in-the-wild vulnerability CVE-2021-30551 patched today was also from the same actor and targeting,” Google Director of Software Engineering Shane Huntley wrote in a Twitter post, referencing that attackers who exploited that vulnerability also took advantage of the vulnerability from CVE-2021-33742. In its release note of the latest Chrome update, Google described the CVE-2021-30551 vulnerability as a “type confusion in V8,” which was reported by Clement Lecigne of Google’s Threat Analysis Group and Sergei Glazunov of Google Project Zero.

The vulnerability was initially discovered on June 4, Google stated, noting that the company “is aware that an exploit for CVE-2021-30551 exists in the wild.” Chrome relies on the JavaScript-based V8 rendering engine for its browser, and the rendering is also common for competing browsers based on the Chromium project, including Microsoft’s Edge.

Even if you’re not on Google Chrome, you’ll want to ensure that you’re running the latest release from the browser of your choice. Most browsers that use Chromium for rendering will also list the Chromium version number, and users should diligently check to see if a patch is available for their browser of choice. If you’re using Microsoft Edge, for example, you’ll want to launch your browser, and navigate to the About page. There, you’ll find the browser version number along with an option to update to the latest version if you’re not on the most current release. Similar procedures can be followed for Opera, Brave, and others that are based on Chromium.

According to Bleeping Computer, this is the sixth zero-day exploit for Chrome in 2021.

Editors' Recommendations

Chuong Nguyen
Silicon Valley-based technology reporter and Giants baseball fan who splits his time between Northern California and Southern…
Google Chrome tops this list of most vulnerable browsers
Google Chrome logo appears over photo of laptop with chart of vulnerabilities.

According to a recent report, Google Chrome is the most vulnerability-ridden browser of all the major players. Chrome also happens to be the most popular browser in the world, accounting for over 60% of usage according to most sources, which means that a larger number of people are at risk until the bugs are fixed.

Every browser suffers from these security weaknesses from time to time, including the increasingly popular Apple Safari, Microsoft Edge, and Mozilla Firefox, but Chrome has had a startlingly high number of weaknesses in 2022. The vulnerability report from Atlas VPN summarized data found in the VulDB vulnerability database. In this year alone, 303 vulnerabilities have been detected in Google Chrome. Firefox came in a distant second with 117, while 103 were found in Edge, and only 26 in Safari.

Read more
Here’s why you need to update your Google Chrome right now
Google Chrome opened on a laptop.

Google has just released a new version of Chrome, and it's crucial that you get your browser updated as soon as possible.

The patch was deployed to fix a major zero-day security flaw that could potentially pose a risk to your device. The latest update is now available for Windows, Mac, and Linux -- here's how to make sure your browser is safe.

Read more
Chrome just added a great new way to protect your passwords
The Google Chrome logo on a black phone which is resting on a red book

Chrome will soon let you use biometric data to autofill forms online, according to Chrome Unboxed. This is something Safari has allowed for years on Mac, but if you use Chrome, you must confirm the details by reentering your password or receiving two-factor authentication notifications on another device.

The password flag was spotted in the Chromium Gerritt repository as an alternative way to authenticate yourself when autofilling your passwords stored in Chrome. It's not meant to be a replacement, and when it does roll out to the public, it appears to be a setting you need to turn on. That could change between now and then, of course.

Read more