Google released emergency security updates to fix the fourth Chrome zero-day vulnerability exploited in attacks since the start of the year. "Google is aware that an exploit for CVE-2023-4863 exists in the wild," the company revealed in a security advisory published on Monday. The new version is currently rolling out to users in the Stable and Extended stable channels, and it's estimated that it will reach the entire user base over the coming days or weeks. Chrome users are advised to upgrade their web browser to version 116.0.5845.187 (Mac and Linux) and 116.0.5845.187/.188 (Windows) as soon as possible, as it patches the CVE-2023-4863 vulnerability on Windows, Mac, and Linux systems. This update was immediately available when BleepingComputer checked for new updates via the Chrome menu > Help > About Google Chrome. The web browser will also check for new updates and automatically install them without requiring user interaction after a restart.
The critical zero-day vulnerability (CVE-2023-4863) is caused by a WebP code library (libwebp) heap buffer overflow weakness whose impact ranges from crashes to arbitrary code execution. The bug was reported by Apple Security Engineering and Architecture (SEAR) and The Citizen Lab at The University of Toronto's Munk School last Wednesday, September 6. Citizen Lab security researchers have often found and disclosed zero-day bugs abused in highly-targeted spyware attacks by government-backed threat actors targeting high-risk individua...