• News/
  • bleepingcomputer-20230911194624

Google fixes another Chrome zero-day bug exploited in attacks

BleepingComputer
·
Published Sep 11, 2023
·
Updated

Google released emergency security updates to fix the fourth Chrome zero-day vulnerability exploited in attacks since the start of the year. "Google is aware that an exploit for CVE-2023-4863 exists in the wild," the company revealed in a security advisory published on Monday. The new version is currently rolling out to users in the Stable and Extended stable channels, and it's estimated that it will reach the entire user base over the coming days or weeks. Chrome users are advised to upgrade their web browser to version 116.0.5845.187 (Mac and Linux) and 116.0.5845.187/.188 (Windows) as soon as possible, as it patches the CVE-2023-4863 vulnerability on Windows, Mac, and Linux systems. This update was immediately available when BleepingComputer checked for new updates via the Chrome menu > Help > About Google Chrome. The web browser will also check for new updates and automatically install them without requiring user interaction after a restart.

The critical zero-day vulnerability (CVE-2023-4863) is caused by a WebP code library (libwebp) heap buffer overflow weakness whose impact ranges from crashes to arbitrary code execution. The bug was reported by Apple Security Engineering and Architecture (SEAR) and The Citizen Lab at The University of Toronto's Munk School last Wednesday, September 6. Citizen Lab security researchers have often found and disclosed zero-day bugs abused in highly-targeted spyware attacks by government-backed threat actors targeting high-risk individua...

Read full article

Affected Software

3 affected components
Google Chrome=116.0.5845.187, >=116.0.5845.187<116.0.5845.187/.188
Mozilla Firefox
Google Chrome=116.0.5845.187/.188
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses Google's emergency security updates to fix a zero-day vulnerability in Chrome.

2

What security implications are discussed?

The article highlights that the vulnerability CVE-2023-4863 is actively being exploited in attacks.

3

What versions of Chrome are affected by this vulnerability?

The affected versions of Chrome are 116.0.5845.187 and 116.0.5845.188.

4

Are any other browsers mentioned as affected?

The article also mentions Mozilla Firefox but does not specify any vulnerabilities for it.

5

What should users do to protect themselves from this vulnerability?

Users should update their Google Chrome browser to the latest version to mitigate the security risk.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203