Latest Chrome 88 Update Includes Important Fix for Zero-Day Vulnerability
Google has released Chrome version 88.0.4324.150 with an important fix for a zero-day vulnerability in the web browser that the company says is likely to have been exploited in the wild.
Google hasn't provided specific details about the heap buffer overflow memory corruption bug known as CVE-2021-21148, and says it won't do so "until a majority of users are updated with a fix."
However, ZDNet notes that the date on which Google says the bug was reported, January 24, is just two days after Google's Threat Analysis Group reported a hacking campaign carried out by North Korean hackers against the cyber-security community.
Some of the attacks involved luring security researchers to a blog where the attackers exploited browser zero-days to run malware on the researchers' systems. On January 28, Microsoft also reported that attackers most likely used a Chrome zero-day for their attacks.
The proximity of the two events has led security researchers to suspect that it was indeed the CVE-2021-21148 zero-day that was used in the attacks. As a result, all users are being advised to use the Chrome menu bar's About Google Chrome option to upgrade their browser to the latest version as soon as possible.
Google Chrome for Mac is a free download available directly from Google's servers. Google Chrome for iOS is a free download for iPhone and iPad available on the App Store. [Direct Link]
Popular Stories
Bloomberg's Mark Gurman has high expectations for Apple's first foldable iPhone.
In his Power On newsletter today, he said the foldable iPhone will be "the most significant overhaul in the iPhone's history."
"iPhone 4, iPhone 6 and iPhone X were clearly a big deal, but this is a whole new design," he said.
Like Samsung's Galaxy Z Fold 7, the foldable iPhone will reportedly open up like ...
March has been an incredibly busy month for Apple, with the company unveiling more than 10 new products and accessories. We said hello to the MacBook Neo at the start of the month, and we bid farewell to the Mac Pro at the end of it.
Nevertheless, there is still a lot more to come this year.
Beyond the usual annual updates to iPhones and Apple Watches, Apple's all-new smart home hub is...
Apple is expected to release two new iPhone apps this year, including an Apple Business app and a Siri app with chatbot-like functionality.
With the Apple Business app, employees at businesses using the new Apple Business platform will be able to install apps for work, view contact information for colleagues, and request support. Apple Business is launching on April 14, and it replaces Apple ...
Popular Stories
Apple has asked Google to investigate setting up servers in its data centers to run a future version of Siri powered by Gemini, The Information reports.
Currently, Apple sends its more complex AI queries to Private Cloud Compute, a system that runs on Apple servers using Apple silicon chips. Today, only 10% of Apple's Private Cloud Compute capacity is said to be in use on average. The usage...
Google's NotebookLM AI-based tool can now turn your research and notes into fully animated "cinematic" videos – an advancement over its original video overview feature that was introduced last year.
Before now, video overviews were limited to generating slideshows of your research and writing, but the new Cinematic Video Overview feature uses Gemini 3, Nano Banana Pro, and Veo 3 models to...
Google's Threat Intelligence Group (GTIG) has a new report out about a powerful iOS exploit kit called "Coruna," which traveled from a surveillance vendor's customer to a Russian espionage group to Chinese cybercriminals, revealing a sophisticated exploit "supply chain" in the process.
Described as one of the most comprehensive iOS exploit toolkits to have been documented publicly, Coruna...