• News/
  • https://www.theregister.com/2023/11/30/chrome_zeroday/

Uh-oh, update Google Chrome – exploit already out there for one of these 6 security holes

The Register
·
Jessica Lyons Hardcastle
·
Published Nov 30, 2023
·
Updated

Google has rolled out six Chrome security fixes including one emergency patch for a bug for which exploit code is already out there. You're encouraged to thus grab the latest updates for the browser. This latest zero-day flaw, tracked as CVE-2023-6345, is a high-severity integer overflow vulnerability in Skia, a popular graphics library used by Chrome. To exploit this bug, an attacker would need to have already compromised the renderer process, at which point they may be able to perform a sandbox escape via a malicious file. "Google is aware that an exploit for CVE-2023-6345 exists in the wild," according to the Chocolate Factory. Google doesn't provide a whole lot of detail about the bug, nor any details about who may be exploiting it and to what nefarious end. It does note, however, that Benoît Sevens and Clément Lecigne, both members of Google's Threat Analysis Group (TAG), found and reported the vulnerability, which indicates it could have been abused to deploy spyware on victims' machines — TAG tracks more than 30 commercial spyware vendors selling exploits and surveillance tools. Meanwhile, networking kit vendor Zyxel issued patches for six vulnerabilities, including three critical 9.8-rated bugs that could allow an unauthenticated attacker to execute some operating system (OS) commands on network-attached storage (NAS) products. The vulnerabilities include: The flaws affect model NAS326, versions 5.21(AAZF.14)C0 and earlier, and can be fixed by updating firmware to V5....

Read full article

Affected Software

5 affected components
Google Chrome
Google Skia
Zyxel NAS326=5.21(AAZF.14)C0
Zyxel NAS542 firmware=5.21(ABAG.11)C0
Apple iMessage
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses an emergency update for Google Chrome addressing six security vulnerabilities, including one for which exploit code is already available.

2

What security implications are discussed in the article?

The article highlights that one of the Chrome vulnerabilities is being actively exploited, posing a significant risk to users who have not updated their browsers.

3

What products or software are affected by the security issues mentioned?

The affected products include Google Chrome, Google Skia, Zyxel NAS326, Zyxel NAS542, and Apple iMessage.

4

How urgent is it to update Google Chrome according to the article?

The article urges users to update Google Chrome immediately due to the presence of exploit code targeting one of the vulnerabilities.

5

Are there specific firmware versions of Zyxel devices that need to be updated?

Yes, Zyxel NAS326 requires firmware version 5.21(AAZF.14)C0 and NAS542 requires version 5.21(ABAG.11)C0 to address the security vulnerabilities.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203