Google Chrome just got an emergency security update — install it right now

Google Chrome on a laptop
(Image credit: Shutterstock)

Google has released a new emergency security update for Chrome to address a high severity zero-day vulnerability that’s currently being exploited by hackers.

As reported by BleepingComputer, the zero-day in question (tracked as CVE-2023-6345) has now been patched in Chrome version 119.0.6045.199/.200 for Windows and version 119.0.6045.199 for Mac and Linux.

In an advisory sent out alongside the emergency security update, the Chrome team explained that it also contains fixes for 6 other security flaws, all of which are high-severity vulnerabilities. With this latest security update for its browser, Google has now patched a total of six zero-day vulnerabilities in this year alone that hackers managed to develop exploits for.

If you haven’t updated Chrome lately, you’re going to want to install this emergency security update as soon as possible since there is a chance — though relatively small — that the zero-day flaw it patches could be used by hackers in their attacks. Even then, you always want to keep your browser up to date as cybercriminals often target users that are running outdated software.


Reader Offer: Save 68% on Aura identity theft protection

Reader Offer: Save 68% on Aura identity theft protection
Aura provides everything you need to protect your identity, data and devices online with malware protection, a password manager and a VPN all included. Tom's Guide readers can save up to 68% when they sign up.

Preferred partner (What does this mean?)

Exploited by hackers but details are scarce

Like with other recent zero-day flaws, Google isn’t saying much as to how hackers are currently exploiting this one in the wild. This is pretty standard though and Apple does the exact same thing with iPhone and Mac zero-days.

The reasoning behind this is pretty simple. If Apple or Google in this case says too much about how hackers are using a zero-day in their attacks, other cybercriminals could follow suit and develop their own exploits. By keeping the details scarce for the time being, Google and other tech giants are giving their users more than enough time to download and install the latest security updates.

The most recent high-severity zero-day flaw in Chrome is an integer overflow bug in the open source, 2D graphics library Skia. Besides Chrome though, it’s also used in other products including ChromeOS on the best Chromebooks, Android and Flutter.

As this flaw was discovered by two security researchers from Google’s Threat Analysis Group (TAG), BleepingComputer believes that hackers could be exploiting it in spyware attacks. However, since these kinds of zero-day flaws are often used by state-sponsored hackers targeting high-profile individuals like journalists and politicians, most people won’t likely need to worry about falling victim to an attack.

Still though, keeping your browser up to date is one of the most important and the easiest way to stay safe from hackers.

How to stay safe from attacks exploiting zero-day flaws

Google Chrome color-coded update button

(Image credit: Google)

Like I mentioned before, installing the latest security updates and patches as soon as they become available is the easiest way to ensure you won’t get caught up in a cyberattack that’s exploiting a recently discovered zero-day flaw.

Although you can manually check for updates by clicking on the three-dot menu, opening Settings and then going to About Chrome, Google also uses a color-coded warning system to let you know when new updates or patches are available. When this happens, you’ll see a bubble next to your profile picture in Chrome. The bubble turns green for a 2-day old update, orange for a 4-day old update and red when an update was released at least a week ago.

Besides keeping your browser up to date, you should also be using the best antivirus software on your Windows PC, the best Mac antivirus software on your Apple computer and one of the best Android antivirus apps on your Android smartphone. This way, you can ensure you’re protected from malware and other viruses.

Zero-day flaws in popular software are more common than you think but in this case, if you keep your browser up to date, you should be fine. It’s just a matter of taking the time to install any new updates that appear instead of putting them off. Fortunately, Chrome updates quickly and reopens all of your current tabs after a restart, so you can pick up right where you left off.

More from Tom's Guide

TOPICS
Anthony Spadafora
Managing Editor Security and Home Office

Anthony Spadafora is the managing editor for security and home office furniture at Tom’s Guide where he covers everything from data breaches to password managers and the best way to cover your whole home or business with Wi-Fi. He also reviews standing desks, office chairs and other home office accessories with a penchant for building desk setups. Before joining the team, Anthony wrote for ITProPortal while living in Korea and later for TechRadar Pro after moving back to the US. Based in Houston, Texas, when he’s not writing Anthony can be found tinkering with PCs and game consoles, managing cables and upgrading his smart home. 

Read more
Apple iPhone 16 Plus Review.
Apple just released an emergency security update for a flaw used in an ‘extremely sophisticated attack’ — update your devices right now
Google Pixel 9 held in the hand.
Google just fixed a zero-day kernel flaw used by hackers and 47 other vulnerabilities — update your Android phone right now
iPhone 16 Pro shown held in hand
Apple just patched its first zero-day flaw of the year — update your iPhone and Mac right now
and image of the Google Chrome logo on a laptop
Billions of Chrome users at risk from new browser-hijacking Syncjacking attack — how to stay safe
A hacker typing quickly on a keyboard
Hackers are posing as Apple and Google to infect Macs with malware — don’t fall for these fake browser updates
Android 12
Google March Android Security Update fixes two high severity vulnerabilities — update now
Latest in Online Security
A magnifying glass on top of the Steam logo in a web browser
Valve just pulled a malicious game demo spreading info-stealing malware from Steam
MacBook Pro 2023
New Mac attack is tricking users into thinking their computer is locked — how to stay safe
Hacker using a stolen social security card
Your Social Security number is a literal gold mine for scammers and identity thieves — here’s how to keep it safe
An open lock depicting a data breach
Half a million teachers hit in major data breach with SSNs, financial data and more exposed — what to do now
Green skull on smartphone screen.
Malicious Android apps with 60 million installs bombarding phones with ads and phishing attacks — how to stay safe
Malware
Dangerous new password-stealing trojan automatically reinstalls itself on infected PCs
Latest in News
Rendered images of rumored foldable iPhone.
Foldable iPhone report just revealed key details — here's what we know
NYTimes Connections
NYT Connections today hints and answers — Saturday, March 23 (#651)
NYT Strands on a cellphone
NYT Strands today — hints, spangram and answers for game #385 (Sunday, March 23 2025)
Nintendo Switch 2
Nintendo Switch 2 rumored specs — here’s what we know so far
iPhone 17 Pro render
iPhone 17 Pro — 7 biggest rumored upgrades
CAD renderings of the Google Pixel 10 Pro XL
Pixel 10 leak could be good news for all Android phones