HT TECH wants to start sending you push notifications. Click allow to subscribe

Google rolls out Chrome security update to patch active zero-day vulnerability

Chrome users can update to v86.0.4240.111 via the browser's built-in update function. And we reccomend you do it right now. 

By: HT TECH
Updated on: Oct 21 2020, 16:00 IST
Project Zero, which is one of Google’s internal security teams, discovered these attacks that were leveraging the FreeType bug. (Forbes)

Google has rolled out Chrome version 86.0.4240.111 which brings about security fixes, including a patch for an actively exploited zero-day vulnerability.

As per the ZDNet report, the zero-day vulnerability is tracked as CVE-2020-15999 and is described as “a memory corruption bug in the FreeType font rendering library that's included with standard Chrome distributions”.

You may be interested in

Mobiles Tablets Laptops
25% OFF
Google Pixel 128GB
  • Black
  • 4 GB RAM
  • 128 GB Storage
₹63,990₹84,999
Buy now
37% OFF
Google Pixel 7 Pro 5G
  • Obsidian
  • 12 GB RAM
  • 128 GB Storage
₹62,990₹99,999
Buy now
7% OFF
Google Pixel 7 5G
  • Obsidian
  • 8 GB RAM
  • 128 GB Storage
₹40,990₹43,999
Buy now
11% OFF
Google Pixel 7A
  • Charcoal
  • 8 GB RAM
  • 128 GB Storage
₹38,990₹43,999
Buy now
21% OFF
Acer Swift Go SFG14 41 NX KG3SI 002 Laptop
  • Pure Silver
  • 8 GB RAM
  • 512 GB SSD
₹58,999₹74,999
Buy now
39% OFF
Acer Aspire 5 A515 57G Laptop
  • Gray
  • 16 GB RAM
  • 512 GB SSD
₹54,949₹89,999
Buy now
22% OFF
Acer Aspire 3 A315 24 NX KDESI 004 Laptop
  • Silver
  • 8 GB RAM
  • 512 GB SSD
₹33,499₹42,999
Buy now
40% OFF
Asus VivoBook 15 X515JA BQ322WS Laptop
  • Transparent Silver
  • 8 GB RAM
  • 512 GB SSD
₹31,350₹51,990
Buy now
34% OFF
Xiaomi Pad 6
  • Mist Blue
  • 6 GB RAM
  • 128 GB Storage
₹26,299₹39,999
Buy now
55% OFF
Lenovo Tab M10 5G
  • Abyss Blue
  • 6 GB RAM
  • 128 GB Storage
₹20,999₹47,000
Buy now
32% OFF
Realme Pad 2
  • Imagination Grey
  • 6 GB RAM
  • 128 GB Storage
₹19,749₹28,999
Buy now
Honor Pad X9
  • Gray
  • 4 GB RAM
  • 128 GB Storage
₹14,999
Check details

Project Zero, which is one of Google’s internal security teams, discovered these attacks that were leveraging the FreeType bug. Project Zero team lead Ben Hawkes also pointed out a threat actor that was abusing this FreeType bug to mount attacks against Chrome users.

Hawkes has urged all app vendors to use the same FreeType library to update their software in case the threat actor “decides to shift attacks against other apps”.

A patch for this bug has been included in FreeType 2.10.4 and has been released.

Also Read: Google Chrome’s Dinosaur game has a new rival, and it is actually better

Chrome users can update to v86.0.4240.111 via the browser's built-in update function. Go to Chrome ‘Menu’, click on ‘Help’ and then go the ‘About Google Chrome’ option for the update.

ZDNet states that the finer details about CVE-2020-15999 active exploitation attempts have not been made public yet and that Google usually “sits on technical details for months to give users enough time to update and keep even the smallest clues from falling into attackers' hands”.

However, since the patch for this zero-day is visible in the source code of FreeType, which is an open source project, it's “expected that threat actors will be able to reverse-engineer the zero-day and come up with their own exploits within days or weeks”.

CVE-2020-15999 is the third Chrome zero-day exploited in the wild in the past twelve months. The first two were CVE-2019-13720 (which happened in October 2019) and CVE-2020-6418 (which happened in February 2020).

Catch all the Latest Tech News, Mobile News, Laptop News, Gaming news, Wearables News , How To News, also keep up with us on ,Twitter, Facebook, , and Instagram. For our latest videos, subscribe to our YouTube channel.

First Published Date: 21 Oct, 16:00 IST

Sale

Mobiles Tablets Laptops
5% OFF
Google Pixel 7A
  • Charcoal
  • 8 GB RAM
  • 128 GB Storage
₹41,990₹43,999
Buy now
48% OFF
Samsung Galaxy S23 FE
  • Mint
  • 8 GB RAM
  • 128 GB Storage
₹41,944₹79,999
Buy now
13% OFF
Samsung Galaxy A55
  • Awesome Iceblue
  • 8 GB RAM
  • 128 GB Storage
₹39,999₹45,999
Buy now
7% OFF
Apple iPhone 15 Pro Max
  • Black Titanium
  • 8 GB RAM
  • 256 GB Storage
₹148,900₹159,900
Buy now
57% OFF
Lenovo Tab M10 5G
  • Abyss Blue
  • 6 GB RAM
  • 128 GB Storage
₹19,999₹47,000
Buy now
28% OFF
Realme Pad 2
  • Imagination Grey
  • 6 GB RAM
  • 128 GB Storage
₹17,999₹24,999
Buy now
20% OFF
Samsung Galaxy Tab S9 5G 256GB
  • Graphite
  • 8 GB RAM
  • 256 GB Storage
₹86,999₹108,699
Buy now
28% OFF
realme Pad 2 WiFi
  • Imagination Grey
  • 6 GB RAM
  • 128 GB Storage
₹17,999₹24,999
Buy now
23% OFF
Infinix INBook X1 Neo XL22 Laptop Intel Celeron Quad Core 8 GB 256 GB SSD Windows 11
  • Blue
  • 4 GB RAM
  • 128 GB SSD
₹22,990₹29,990
Buy now
28% OFF
Asus ROG Strix G17 G712LU EV078T Laptop
  • Blue
  • 16 GB RAM
  • 1 TB SSD
₹81,990₹113,990
Buy now
40% OFF
Samsung Galaxy Book Go Laptop
  • Silver
  • 4 GB RAM
  • 128 GB SSD
₹28,690₹47,990
Buy now
22% OFF
Asus ROG Strix G15 G513RC HN085WS Laptop
  • Electro Punk
  • 16 GB RAM
  • 1 TB SSD
₹70,990₹90,990
Buy now
NEXT ARTICLE BEGINS