Update Google Chrome to Protect your Business from this Zero Day Threat
Google’s Chrome browser, used by over three billion users worldwide, recently encountered its first Zero-Day exploit of the year. In response, Google has issued an urgent update to address the discovered vulnerability, CVE-2023-2033, which affects Chrome on Windows, Mac, and Linux platforms. The exploit, identified as a “Type Confusion in V8,” occurs when an incompatible method accesses a resource initialised by a different method, potentially exposing the browser’s memory to unauthorised access. The vulnerability was discovered by Google’s Threat Analysis Group, but unfortunately, a patch was not developed before the first exploits began.
To protect your browser, it is crucial to update Chrome immediately. To do so, click the overflow menu bar (three vertical dots) in the browser’s top right corner, then navigate to Help > About Google Chrome. This action will force Chrome to check for browser updates. After the update is complete, be sure to restart the browser to ensure full protection. Google has made significant progress in patching Chrome vulnerabilities this year, as evidenced by the fact that it took until April for the first Zero-Day exploit to emerge. In comparison, Chrome experienced 15 Zero-Day exploits in 2021 and nine in 2022.
Google’s success in reducing vulnerabilities can be attributed to its robust reporting system and high bounties paid for the discovery of security issues, incentivising researchers to disclose their findings to Google rather than hackers. In 2022, Google paid over $12 million in bug bounties, including a record single bounty of $605,000 for a critical exploit. Despite this progress, Chrome’s dominance in the browser market means it remains a prime target for attackers. Google warned in March 2022 that Zero-Day attacks would likely continue to rise, so users must stay vigilant and promptly apply updates to ensure the security of their browsing experience.
To ensure that your business machines are protected from Zero Day Threats such as this one, ensure that you are protected with Endpoint Detection & Response, One2Call’s EDR solution uses artifical inteligence to proactivly monitor your endpoints for unusual or malicious activity to prevent them from being targeted by previously unknown threats. Click the link below to find out more about Endpoint Detection & Response, or contact us to discuss your business Cyber Security.
Latest News Stories
(Updated 12/04/23 – 09:30BST) SECURITY ALERT: 3CX Desktop App Security Vulnerability
UPDATE 12/04/2023 - 09:30BST: Mandiant's initial investigation into the 3CX intrusion and supply chain attack attributes the activity to a North Korean-linked group, UNC4736. They discovered that the attackers infected targeted 3CX systems with Windows-based TAXHAUL...
FBI Issues Cyber Security Warning over using Public Charging Points
The FBI has issued a warning urging individuals and businesses to avoid using public USB ports due to the risk of malware infections. According to a tweet from the Denver FBI office (as reported by CNBC), cyber criminals have exploited charging stations and points...
New Cyber Alert – New Nexus Trojan on Android, Attacking Mobile Banking Accounts
The new Android trojan is being spread through phishing pages disguised as legitimate websites called YouTube Vanced. The botnet, named Nexus, was first made available on a forum in January 2023 for a monthly fee of $3,000 and was described as a "very new" project...
Our Customers
Testimonials
Julia Wallace-Ross, Cornerstones Education
So grateful for Jordan coming out so quickly and helping me out.
Cliff College
It’s clear that Jordon prioritized our needs as a College. He took on a task that wasn’t easy and sorted it quickly.
Pete Richardson, DALP
Always provide very prompt support. Excellent.