Chrome's third exploited zero-day this year has also been fixed

Google Chrome browser app on iPhone
(Image credit: Shutterstock)

Google is urging Chrome users to apply a security update to their browsers as it pushes a fix for a zero-day vulnerability that has known exploits.

Update 114.0.5735.106 for Mac and Linux, or 114.0.5735.110 for Windows, has addressed CVE-2023-3079 which was reported to Google days before a patch was released to the public on June 5.

The vulnerability was given a high severity rating, hence the fast-paced approach to issuing a fix, though precise details remain under wraps as the company waits for more users to apply the fix (and protect themselves against hackers).

Update Google Chrome now

The CVE description reads: “Type confusion in V8 in Google Chrome prior to 114.0.5735.110 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.”

In its announcement, Google admitted that it is “aware that an exploit for CVE-2023-3079 exists in the wild,” thanking Clément Lecigne of the company’s Threat Analysis Group for reporting the vulnerability on June 1.

This isn’t the first time Google has had issues with the V8 JavaScript engine, with the browser’s first zero-day of 2023 also attributable to that. Its second zero-day saw a C++ 2D graphics library issue rectified.

While Google is typically quick to respond to bugs, a lengthy delay can occur between a bug being reported and details about it being shared, because the company wants to ensure that consumers have applied the relevant fixes first.

The announcement reads: “Access to bug details and links may be kept restricted until a majority of users are updated with a fix. We will also retain restrictions if the bug exists in a third party library that other projects similarly depend on, but haven’t yet fixed.”

Craig Hale

With several years’ experience freelancing in tech and automotive circles, Craig’s specific interests lie in technology that is designed to better our lives, including AI and ML, productivity aids, and smart fitness. He is also passionate about cars and the decarbonisation of personal transportation. As an avid bargain-hunter, you can be sure that any deal Craig finds is top value!

Read more
A finger touching the google chrome icon in the Windows 10 start menu
A new Chrome browser highjacking attack could affect billions of users - here's how to fight it
An option to add Ambient Music buttons to the iOS 18.4 Control Center.
Apple fixes dangerous zero-day used in attacks against iPhones and iPads
Apple's new "Share Item Location" feature for AirTags.
Apple security alert - zero-day patched, so update your devices now
Apple Siri
Update your Apple device now: iOS 18.3.2 fixes a flaw that could be exploited by hackers
Chrome icon on Android
Google Chrome extensions hack may have started much earlier than expected
chrome firefox extensions
Google Chrome extensions hit in major attack - dozens of developers affected, so be on your guard
Latest in Security
cybersecurity
Chinese government hackers allegedly spent years undetected in foreign phone networks
Data leak
A major Keenetic router data leak could put a million households at risk
Code Skull
Interpol operation arrests 300 suspects linked to African cybercrime rings
Insecure network with several red platforms connected through glowing data lines and a black hat hacker symbol
Multiple routers hit by new critical severity remote command injection vulnerability, with no fix in sight
Code Skull
This dangerous new ransomware is hitting Windows, ARM, ESXi systems
An abstract image of a lock against a digital background, denoting cybersecurity.
Critical security flaw in Next.js could spell big trouble for JavaScript users
Latest in News
Hornet swings their weapon in mid air
Hollow Knight: Silksong gets new Steam metadata changes, convincing everyone and their mother that the game is finally releasing this year
OpenAI logo
OpenAI just launched a free ChatGPT bible that will help you master the AI chatbot and Sora
Monster Hunter Wilds
Monster Hunter Wilds Title Update 1 launches in early April, adding new monsters and some of the best-looking armor sets I need to add to my collection
Zotac Gaming RTX 5090 Graphics Card
Nvidia Blackwell stock woes are compounded by price hikes as more RTX 5090 GPUs soar in pricing, and I’m sick and tired of it all at this point
A collage of Elizabeth Olsen's Scarlet Witch and Tatiana Maslany's She-Hulk
Marvel fans are already tired of Doomsday and Secret Wars cast gossip as two more superheroes get linked with roles in the next two Avengers movies
Four operators survey Verdansk. One holds a sniper rifle, one binoculars, another holds is landing with their parachute, while the last wears a skull mask
New Call of Duty: Warzone trailer shows a beautiful rebuilt Verdansk, but some fans want more: 'it won't be the same unfortunately'