Dangerous Chrome zero-day exploit discovered — update your browser now

Laptop computer displaying logo of Google Chrome, a cross-platform web browser developed by Google.
(Image credit: Shutterstock)

It seems like it was just yesterday that we told you to update Google Chrome because of a zero-day flaw being exploited. But we promise it wasn’t — it was five days ago.

According to Bleeping Computer, Google has now updated a second zero-day vulnerability. This is based on an update from Google yesterday (April 18) that fixes an exploit for CVE-2023-2136, which is a “high-severity integer overflow” exploit.

Integer overflows are when a computer program performs a calculation that results in an answer larger than the available space. This results in the program providing incorrect numbers, which can cause the program to behave erratically. This is what attackers are able to exploit — the erratic behavior.

This particular vulnerability occurs in Skia, which is an open-source 2D graphics library owned by Google and used in Chrome. Practically, it is used to give Chrome the ability to render “graphics, text, shapes, images, and animations.” So it is a key component of how the web browser operates.

Unfortunately, we don’t know much beyond that in terms of how the exploit works. Google’s standard operating procedure for these bugs is to identify them and fix them. They typically don’t divulge much information about the bug if it is being actively exploited.

The good news is that there is an easy way to keep yourself safe — download the latest update. The Stable Channel Update for Desktop - 112.0.5615.137 fixes CVE-2023-2136 along with seven other fixes and is currently available for Windows and macOS users. A Linux update is expected to come soon according to Google.

Google’s second zero-day fix in a week

Of course, this isn’t the first time we’ve reported a zero-day flaw on Chrome recently. Last week we reported on exploit CVE-2023-2033, which Google has also subsequently released an update for. 

Again, because this is an actively exploited bug, Google didn’t release many details on the exploit. All we know is that it is a type confusion exploit in the Chrome V8 Javascript engine. These exploits can lead to memory access outside the normal bounds of the program.

While it’s certainly scary to see these exploits found in quick succession, the good news is this is only the second such exploit this year. So hopefully, it is just a weird coincidence that they were found so close together rather than a sign that Chrome is more vulnerable than usual. 

How to keep your browser protected from hackers

The most important thing you can do when these flaws are discovered is to update your browser. Regularly updating your browser won’t keep you necessarily safe from everything, but it will keep you as safe as possible.

Google Chrome color-coded update button

(Image credit: Google)

If you haven’t installed the latest update yet, you should see a bubble next to your profile picture in Chrome. This bubble is color-coded based on how long it has been since the update became available. Green means it's just two days old, orange means it's now a four-day-old update and red means that the update is at least a week old. Don’t let it get to red.

To download the latest version of Chrome, all you need to do is click on the bubble. If you do that, Chrome will install the update the next time you relaunch your browser. 

You can also manually update Chrome. To do this, just click on the three dots next to your profile picture, then click Help and then click About Google Chrome. This takes you to Chrome’s settings page where you can check to see if you’re running the latest version of Chrome.

Keeping your browser up to date is essential to protecting your computer from malware and other viruses. But you also want to install the best antivirus software on your PC or the best Mac antivirus software on your Apple computer to make sure all your bases are covered.

More from Tom's Guide

Malcolm McMillan
Streaming Editor

Malcolm has been with Tom's Guide since 2022, and has been covering the latest in streaming shows and movies since 2023. He's not one to shy away from a hot take, including that "John Wick" is one of the four greatest films ever made.

Read more
Google Pixel 9 held in the hand.
Google just fixed a zero-day kernel flaw used by hackers and 47 other vulnerabilities — update your Android phone right now
Apple iPhone 16 Plus Review.
Apple just released an emergency security update for a flaw used in an ‘extremely sophisticated attack’ — update your devices right now
and image of the Google Chrome logo on a laptop
Billions of Chrome users at risk from new browser-hijacking Syncjacking attack — how to stay safe
Android 12
Google March Android Security Update fixes two high severity vulnerabilities — update now
iPhone 16 Pro shown held in hand
Apple just patched its first zero-day flaw of the year — update your iPhone and Mac right now
Windows
240 million Windows 10 users are vulnerable to six different hacker exploits — protect yourself now
Latest in Online Security
Graphic screen displaying malware detection warning
This dangerous new Windows malware hides from your antivirus while impersonating a popular PC brand
23andME box
23andMe has declared bankruptcy — here's how to delete your data now
A magnifying glass on top of the Steam logo in a web browser
Valve just pulled a malicious game demo spreading info-stealing malware from Steam
A man filing his taxes electronically on a laptop
AI-powered tax scams are here - how to stay safe from deepfakes, phishing and more this tax season
MacBook Pro 2023
New Mac attack is tricking users into thinking their computer is locked — how to stay safe
Hacker using a stolen social security card
Your Social Security number is a literal gold mine for scammers and identity thieves — here’s how to keep it safe
Latest in News
Graphic screen displaying malware detection warning
This dangerous new Windows malware hides from your antivirus while impersonating a popular PC brand
Kevin Costner in Field of Dreams
Why I watch ‘Field of Dreams’ on baseball’s opening day every year
Nintendo Switch 2
Nintendo Switch 2 pre-order date just revealed by Best Buy — here's when you can get yours
iphone 17 renders showing off rear and camera bump
iPhone 17 just tipped for this major display upgrade — thanks to Samsung
Galaxy S25 Edge dummy unit from side angle
Samsung Galaxy S25 Edge colors shown off in leaked renders — here’s the options
Nothing Phone 3a Pro rear side showing the camera
Nothing Phone 3a could start charging for using AI features — and I think that's a terrible idea