Google just released emergency Chrome fix for zero-day bug being used by hackers — update right now

and image of the Google Chrome logo on a laptop
(Image credit: Shutterstock)

Google has fixed a new zero-day flaw in Chrome that hackers are using in their attacks just days after addressing a similar flaw.

As reported by BleepingComputer, these new emergency security updates fix an out-of-bounds write bug (tracked as CVE-2024-4761) in Chrome’s V8 JavaScript engine. These types of flaws typically occur when a program is allowed to write data outside of a specified array or buffer, which can potentially lead to unauthorized access, arbitrary code execution or even crashes.

In a new security advisory, Google explained that it is aware of the fact that an exploit for this zero-day exists in the wild. However, just like with the use-after-free bug the search giant patched only a few days ago, details about the flaw itself are being “restricted until a majority of users are updated with a fix.”

Google has patched this new zero-day with the release of Chrome version 124.0.6367.207/.208 for Mac and Windows, and updates will begin rolling out to all users over the coming days or even weeks.

How to stay safe from zero-day attacks

Best antivirus software

(Image credit: Shutterstock)

Unlike with other cyberattacks, there isn’t much you can do to stay safe from attacks that leverage zero-day vulnerabilities besides keeping your browser and other software updated to the latest version. 

In Chrome, Google uses a color-coded warning system to inform you that a new update is available for its browser. If you look at your profile picture, a bubble will appear next to it when there’s an update. It will be green for a 2-day-old update, orange for a 4-day-old update and red when an update was released at least a week ago.

For those who don’t want to wait for this bubble to appear, you can also manually check to see if an update for Chrome is available by clicking on the three-dot menu in the upper right-hand corner of your browser. From there, you need to open Settings and then go to About Chrome. If an update is ready to be installed, Chrome will automatically begin downloading it, and it will be applied the next time you restart your browser.

In addition to keeping Chrome up to date, you should also consider using the best antivirus software on your PC, the best Mac antivirus software on your Mac and one of the best Android antivirus apps on your Android smartphone. Combining regular software updates with antivirus software will protect you and your devices from the latest threats.

So far this year, this is the sixth zero-day flaw in Chrome that Google has discovered and subsequently patched. These kinds of stories may seem scary at first, but by finding and fixing these flaws, the search giant is ensuring that users won’t be attacked by hackers when using its browser.

More from Tom's Guide

Network
Arrow
Intego
Norton
Contract Length
Arrow
Showing 2 of 2 deals
Filters
Arrow
Anthony Spadafora
Managing Editor Security and Home Office

Anthony Spadafora is the managing editor for security and home office furniture at Tom’s Guide where he covers everything from data breaches to password managers and the best way to cover your whole home or business with Wi-Fi. He also reviews standing desks, office chairs and other home office accessories with a penchant for building desk setups. Before joining the team, Anthony wrote for ITProPortal while living in Korea and later for TechRadar Pro after moving back to the US. Based in Houston, Texas, when he’s not writing Anthony can be found tinkering with PCs and game consoles, managing cables and upgrading his smart home. 

Read more
Google Pixel 9 held in the hand.
Google just fixed a zero-day kernel flaw used by hackers and 47 other vulnerabilities — update your Android phone right now
Apple iPhone 16 Plus Review.
Apple just released an emergency security update for a flaw used in an ‘extremely sophisticated attack’ — update your devices right now
iPhone 16 Pro shown held in hand
Apple just patched its first zero-day flaw of the year — update your iPhone and Mac right now
and image of the Google Chrome logo on a laptop
Billions of Chrome users at risk from new browser-hijacking Syncjacking attack — how to stay safe
Android 12
Google March Android Security Update fixes two high severity vulnerabilities — update now
Windows
240 million Windows 10 users are vulnerable to six different hacker exploits — protect yourself now
Latest in Online Security
23andME box
23andMe has declared bankruptcy — here's how to delete your data now
A magnifying glass on top of the Steam logo in a web browser
Valve just pulled a malicious game demo spreading info-stealing malware from Steam
A man filing his taxes electronically on a laptop
AI-powered tax scams are here - how to stay safe from deepfakes, phishing and more this tax season
MacBook Pro 2023
New Mac attack is tricking users into thinking their computer is locked — how to stay safe
Hacker using a stolen social security card
Your Social Security number is a literal gold mine for scammers and identity thieves — here’s how to keep it safe
An open lock depicting a data breach
Half a million teachers hit in major data breach with SSNs, financial data and more exposed — what to do now
Latest in News
Apple Watch Ultra 2
Apple Watch Ultra 3 just tipped for two major upgrades
NYTimes Connections
NYT Connections today hints and answers — Tuesday, March 25 (#653)
A first look at Amazon's Fallout TV series coming to Prime Video
‘Fallout’ season 3 plans are reportedly being made — while season 2 is still filming
Surface Laptop 7 from the front
Amazon just gave Surface Laptop 7 a 'frequently returned' label — here's what's going on
New emojis with iOS 18.4 beta release.
iOS 18.4 beta brings 8 new emoji to your iPhone — here's all the new options
23andME box
23andMe has declared bankruptcy — here's how to delete your data now