Latest Chrome 88 Update Includes Important Fix for Zero-Day Vulnerability - MacRumors
Skip to Content

Latest Chrome 88 Update Includes Important Fix for Zero-Day Vulnerability

Google Chrome Material Icon 450x450Google has released Chrome version 88.0.4324.150 with an important fix for a zero-day vulnerability in the web browser that the company says is likely to have been exploited in the wild.

Google hasn't provided specific details about the heap buffer overflow memory corruption bug known as CVE-2021-21148, and says it won't do so "until a majority of users are updated with a fix."

However, ZDNet notes that the date on which Google says the bug was reported, January 24, is just two days after Google's Threat Analysis Group reported a hacking campaign carried out by North Korean hackers against the cyber-security community.

Some of the attacks involved luring security researchers to a blog where the attackers exploited browser zero-days to run malware on the researchers' systems. On January 28, Microsoft also reported that attackers most likely used a Chrome zero-day for their attacks.

The proximity of the two events has led security researchers to suspect that it was indeed the CVE-2021-21148 zero-day that was used in the attacks. As a result, all users are being advised to use the Chrome menu bar's About Google Chrome option to upgrade their browser to the latest version as soon as possible.

Google Chrome for Mac is a free download available directly from Google's servers. Google Chrome for iOS is a free download for iPhone and iPad available on the App Store. [Direct Link]

Popular Stories

duckduckgo no ai

DuckDuckGo's 'No AI' Search Traffic Climbs as Users Reject Google's AI Overhaul

Friday May 29, 2026 3:55 pm PDT by
Privacy-focused search engine DuckDuckGo has seen a surge in demand for its "No AI" search option in the wake of Google's May 19th I/O announcements. Google debuted a new "intelligent" search box reimagined with AI. It features AI suggestions as an upgrade to autocomplete, support for follow-up questions, expanded Personal Intelligence for connecting Gmail and Google Photos, and Search agents. ...
android iphone airdrop quickshare

Google Expands AirDrop Support to More Android Phones

Tuesday June 2, 2026 12:24 pm PDT by
Google today said its Quick Share feature that allows Android and iPhone users to exchange files with AirDrop is expanding to more devices. Quick Share is now available on the following Android smartphones. Samsung: Galaxy S26, S26+, S26 Ultra Galaxy S25, S25+, S25 Ultra, S25 Edge (new) Galaxy S24, S24+, S24 Ultra (new) Galaxy Z Flip7 (new) Galaxy Z Fold7 (new) Galaxy...
Apple Silicon AI Optimized Feature Siri

Apple's Overhauled Siri Will Reportedly Run on Nvidia's Blackwell Chips

Thursday June 4, 2026 2:38 am PDT by
Apple will rely on Google's fleet of Nvidia chips to power its overhauled version of Siri when it launches in September, according to a new report from The Information. Last week, the outlet reported that Apple plans to highlight the on-device AI capabilities of its devices at WWDC next week, but queries that require cloud-based processing will still fall back on one of Google's large Gemini ...

Top Rated Comments

techpr Avatar
70 months ago
I stopped using and uninstalled Chrome in 2020. Safari and Firefox for me.
Score: 3 Votes (Like | Disagree)
macdos Avatar
70 months ago
Always these "overflows", there's no end to it, it is just like Flash.

Code in apps and OSs should be rewritten from scratch with something else than C and derivatives, something that doesn't use "pointers", something that is tight from start.
Score: 2 Votes (Like | Disagree)
70 months ago
Does this zero-day vulnerability only affect Chrome, or does it affect all Chromium based browsers?
Score: 2 Votes (Like | Disagree)
70 months ago

Google hasn't provided specific details about the heap buffer overflow memory corruption bug known as CVE-2021-21148, and says it won't do so "until a majority of users are updated with a fix."
"We have discovered a bug where Apple's tracking option will cause Chrome to crash, so we are trying to disable it!"

Internet irony might be lost on this one.

Curious as to what others uses as a backup browsers to Safari? I'm looking to de-google thus Chrome is out, but need a Chromium browser for the occasional website where Safari doesn't place nice.
Firefox with uMatrix and Facebook Container. It works wonders to clear the tracking gunk.
Score: 1 Votes (Like | Disagree)
chucker23n1 Avatar
70 months ago

What about WebKit based browsers like Safari? Is the exploit something Google added since forking for Chromium, or is it something that was separately fixed already for WebKit?
If the bug is in V8, WebKit won't be affected because WebKit's JS engine was never V8. (Chrome choosing its own JS engine happened long before it forked WebKit to Blink.)

If the bug is outside V8, it is indeed possible that WebKit is affected.
Score: 1 Votes (Like | Disagree)
luvbug Avatar
70 months ago
The Brave browser has already updated the stable release to this latest Chrome build. Just FYI. Edit: "latest Chromium build", which tracks the Chrome build exactly, but excludes the closed-source bits.
Score: 1 Votes (Like | Disagree)