Security Bulletin

Google Chrome Zero-Day Impacting 3 Billion Users

April 17, 2023
Elpha Secure

Google has recently released an emergency security update for Chrome to address a zero-day vulnerability that has been observed in the wild since the start of the year. This vulnerability, CVE-2023-2033, is a high-severity type confusion weakness in the Chrome V8 JavaScript engine. A high-severity type confusion weakness can lead to out-of-bounds memory access, which can cause programs to crash or sensitive data to leak. Additionally, threat actors can exploit this vulnerability for arbitrary code execution on compromised devices.

Google has advised users to upgrade to version 112.0.5615.121 as soon as possible, which addresses CVE-2023-2033 on Windows, Mac, and Linux systems.

Chrome users can check for new updates from the Chrome menu > About Google Chrome, or wait for automatic updates to be installed after a restart.

This vulnerability is currently being exploited by cybercriminals. The full nature of the attacks leveraging this vulnerability has not yet been disclosed, but it is vital that all Chrome users upgrade to the latest version to protect against any potential exploit.

Elpha Secure's unique combination of cyber insurance, endpoint software, and 24/7 Security Operations Center (SOC) provides a holistic approach to your organization's security. We leverage traditional risk transfer, technology, and human intelligence to alert you of the latest vulnerabilities and assist with mitigation.

Disclaimer: The information contained herein is not intended to constitute legal or other professional advice and should not be relied upon in place of consultation with your own legal and security advisors.

> Back Button An arrow to close the mobile menu