Google this week is addressing a wide range of security holes in Chrome, now officially at version 128, including a notably serious issue that threat actors might be already exploiting.
“The Chrome team is delighted to announce the promotion of Chrome 128 to the stable channel for Windows, Mac and Linux,” reads the latest entry on the Chrome Releases blog. “This will roll out over the coming days/weeks.”
Chrome 128.0.6613.84/.85 (for Windows and Mac) and Chrome 128.0.6613.84 (for Linux) contain “a number of fixes and improvements,” including more than three dozen security fixes, according to the advisory.
One bug found in the web browser’s V8 JavaScript engine is said to have a working exploit developed by hackers.
“Google is aware that an exploit for CVE-2024-7971 exists in the wild,” says the web giant.
In typical fashion, the company doesn’t discuss the issue at length, giving end-users time to patch up while also restricting potential attacks by opportunistic hackers.
Chrome 128.0.6613.88 for Android contains the same fixes, while Chrome for iOS 128.0.6613.92 only packs the usual “stability and performance improvements.”
There is no indication that hackers are exploiting this particular V8 weakness, but users are advised to update their Chrome browsers the first chance they get.
Bitdefender always recommends you deploy security updates the moment they’re available – especially when the vulnerabilities addressed are labelled serious, or potentially exploited by threat actors in the wild.
Staying up to date greatly reduces the attack surface for hackers, as most maintenance updates include important security fixes. Unpatched flaws in Google Chrome have been known to lead to spyware infections in targeted attacks. For peace of mind, consider a dedicated security solution for your personal devices.
tags
Filip has 15 years of experience in technology journalism. In recent years, he has turned his focus to cybersecurity in his role as Information Security Analyst at Bitdefender.
View all postsDecember 27, 2024
December 24, 2024
December 19, 2024