Billions at risk from Google Chrome security flaw — update your browser right now

Google Chrome on a laptop
(Image credit: Shutterstock)

Google has released a new emergency security update for Chrome to fix the fifth zero-day vulnerability in its browser so far this year.

As reported by BleepingComputer, this new zero-day (tracked as CVE-2023-5217) is particularly troubling as hackers have already devised a way to exploit it in their attacks. This is why you’re going to want to update Chrome immediately or risk falling victim yourself.

In a recent security advisory, Google’s Chrome team explained that the latest version of its browser (117.0.5938.132) for Windows, Mac and Linux contains a total of 10 security fixes to patch three high severity vulnerabilities.

According to the advisory, it may take days or even weeks until this emergency security update rolls out to all Chrome users. However, when I went to Chrome’s settings menu and clicked on About Chrome, my browser downloaded the update immediately. As such, if you don’t see the update yet, you should keep checking for it as it’s one you aren’t going to want to put off installing.

Used to install spyware

A spyware alert displaying on a smartphone.

(Image credit: David MG/Shutterstock)

Of the three vulnerabilities addressed in this new emergency security update, CVE-2023-5217 is the result of a heap buffer overflow weakness in the VP8 encoding in libvpx. It was discovered by Google’s own Clément Lecigne from the company’s Threat Analysis Group (TAG) and can lead to app crashes or arbitrary code execution.

If you’re unfamiliar with TAG, its security researchers have a knack for finding serious zero-days that are used in spyware attacks against high profile individuals like politicians and journalists. In a post on X, TAG’s Maddie Stone confirmed that the zero-day fixed in this latest Chrome update was exploited by hackers to install spyware.

As is often the case with zero-days like this one, Google has yet to share any additional information regarding how it’s been used in attacks in the wild. The reason being is that this gives Chrome’s large install base of 3.22 billion users (according to Statista) additional time to update their browsers. 

Once details about an attack are made public, other copycat hackers may come up with their own exploits for a vulnerability. From here, they then target users that have not yet updated their software to the latest version. Hence, the importance of updating Google Chrome right now.

How to stay safe from attacks exploiting vulnerabilities in Chrome

Google Chrome color-coded update button

(Image credit: Google)

Just like with the recent zero-day flaws patched by Apple, the most important thing you can do to stay safe in this situation is to update Chrome to the latest version as soon as the update arrives in your browser. 

While you can manually check for updates by clicking on the three-dot menu, opening Settings and then going to About Chrome, Google also uses a color-coded warning system to let you know when new updates for its browser are available. These appear as a bubble next to your username and its color changes based on when the update was released. A green bubble means the update is two days old while orange is for a 4-day old update and red shows the update was released at least a week ago. If you need more help though, you can always check out our guide on how to update Google Chrome.

In addition to keeping your browser up to date, you should also be using the best antivirus software on your PC, the best Mac antivirus software on your Apple computer and one of the best Android antivirus apps on your Android smartphone. By using antivirus software alongside installing the latest security updates, you can ensure you’re protected against all manner of cyberattacks.

We probably won’t find out more about how this vulnerability was exploited to install spyware but just knowing that this happened should be enough to convince you that this update isn’t one you want to skip.

More from Tom's Guide

TOPICS
Anthony Spadafora
Managing Editor Security and Home Office

Anthony Spadafora is the managing editor for security and home office furniture at Tom’s Guide where he covers everything from data breaches to password managers and the best way to cover your whole home or business with Wi-Fi. He also reviews standing desks, office chairs and other home office accessories with a penchant for building desk setups. Before joining the team, Anthony wrote for ITProPortal while living in Korea and later for TechRadar Pro after moving back to the US. Based in Houston, Texas, when he’s not writing Anthony can be found tinkering with PCs and game consoles, managing cables and upgrading his smart home. 

Read more
Google Pixel 9 held in the hand.
Google just fixed a zero-day kernel flaw used by hackers and 47 other vulnerabilities — update your Android phone right now
Apple iPhone 16 Plus Review.
Apple just released an emergency security update for a flaw used in an ‘extremely sophisticated attack’ — update your devices right now
and image of the Google Chrome logo on a laptop
Billions of Chrome users at risk from new browser-hijacking Syncjacking attack — how to stay safe
and image of the Google Chrome logo on a laptop
Over 600,000 Chrome users at risk after 16 browser extensions compromised by hackers — what you need to know
iPhone 16 Pro shown held in hand
Apple just patched its first zero-day flaw of the year — update your iPhone and Mac right now
and image of the Google Chrome logo on a laptop
Popular Chrome extensions hijacked by hackers in widespread cyberattack — 3.2 million at risk
Latest in Browsers
iPhone 16 Pro Max shown in hand
Your iPhone has a custom voice command feature — here's how to use it
iPhone 16 Pro Max shown in hand
You can change your iPhone's default browser — here's how
Google Chrome on Android
How to stop your personal data from appearing in Google searches
Opera Air
I just tested the world’s first mindful browser — it’s calmly convinced me to ditch Google Chrome
A photo of the Google Chrome logo on a white background, displayed on the screen of a large MacBook Pro which is situated on a table with green foliage behind.
Google Chrome just got three new modes — and it's a game changer for performance
Google Calendar app on iPhone
Google Calendar just got the dark mode we’ve been waiting for — here’s how to activate it
Latest in News
NYTimes Connections
NYT Connections today hints and answers — Tuesday, March 25 (#653)
A first look at Amazon's Fallout TV series coming to Prime Video
‘Fallout’ season 3 plans are reportedly being made — while season 2 is still filming
Surface Laptop 7 from the front
Amazon just gave Surface Laptop 7 a 'frequently returned' label — here's what's going on
New emojis with iOS 18.4 beta release.
iOS 18.4 beta brings 8 new emoji to your iPhone — here's all the new options
23andME box
23andMe has declared bankruptcy — here's how to delete your data now
half-life alyx
Latest Half-Life 3 rumors point to a 2025 release — and maybe pigs will fly