• News/
  • https://www.bleepingcomputer.com/news/security/google-chrome-emergency-update-fixes-6th-zero-day-exploited-in-2023/

Google Chrome emergency update fixes 6th zero-day exploited in 2023

BleepingComputer
·
Sergiu Gatlan
·
Published Nov 28, 2023
·
Updated

Google has fixed the sixth Chrome zero-day vulnerability this year in an emergency security update released today to counter ongoing exploitation in attacks. The company acknowledged the existence of an exploit for the security flaw (tracked as CVE-2023-6345) in a new security advisory published today. "Google is aware that an exploit for CVE-2023-6345 exists in the wild," the company said. The vulnerability is now addressed in the Stable Desktop channel, with patched versions rolling out globally to Windows users (119.0.6045.199/.200) and Mac and Linux users (119.0.6045.199). Although the advisory says the security update may take days or weeks to reach the entire user base, it was available immediately when BleepingComputer checked for updates earlier today. The web browser will check for new updates automatically and install them after the next launch for users who don't want to do it manually.

This high-severity zero-day vulnerability stems from an integer overflow weakness within the Skia open-source 2D graphics library, posing risks ranging from crashes to the execution of arbitrary code (Skia is also used as a graphics engine by other products like ChromeOS, Android, and Flutter). The bug was reported on Friday, November 24, by Benoît Sevens and Clément Lecigne, two security researchers with Google's Threat Analysis Group (TAG). Google TAG is known for uncovering zero-days, often exploited by state-sponsored hacking groups in spyware campaigns targeting high-profile ...

Read full article

Affected Software

2 affected components
Google Chrome (Trace Event)=119.0.6045.199
Google Chrome (Trace Event)=119.0.6045.200

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses an emergency update released by Google to fix the sixth zero-day vulnerability in Chrome for 2023.

2

What security implications are discussed in the article?

The article highlights the ongoing exploitation of a security flaw in Google Chrome, tracked as CVE-2023-6345.

3

Which version of Google Chrome is affected by the zero-day vulnerability?

The zero-day vulnerability affects all currently supported versions of Google Chrome.

4

How frequently have zero-day vulnerabilities been reported in Google Chrome this year?

The article notes that this is the sixth zero-day vulnerability reported in Google Chrome in 2023.

5

What steps should users take following this emergency update?

Users are advised to update their Google Chrome browser immediately to mitigate the risks associated with the zero-day vulnerability.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203