Google releases emergency update for Chrome

Google released a new security update for its Chrome web browser for desktop systems and Android. The update fixes a security issue that is exploited in the wild, according to Google.

The issue affects Chrome for Windows, Linux, Mac and Android, according to Google.

The security issue affects Chromium, the source that Chrome and other browsers, such as Microsoft Edge, Brave or Opera use. As such, it is not Chrome-specific, but an issue that affects all these browsers.

Chrome Download Now

Chrome users should update the web browser immediately to resolve the issue.

How to install the Chrome security update

Chrome up to date on Windows

Google Chrome installs updates automatically by default, but this does not happen in real-time. Desktop versions of Chrome support manual updates, and this is how it is done:

  1. Open the Chrome web browser on the computer.
  2. Load chrome://settings/help in the browser’s address bar, or, select Menu > Help > About Google Chrome if you prefer this way.
  3. Chrome displays the installed version and runs a check for updates. Any new update is downloaded and installed at this point.
  4. A restart is required to complete the process.

One of the following Chrome version needs to be listed on the Help page after the update:

  • Google Chrome on Mac or Linux: 107.0.5304.121
  • Chrome on Windows: 107.0.5304.121 or 107.0.5304.122
  • Chrome Extended Stable channel: 106.0.5249.199

There is no option to install a Chrome update for Android using the method described above.

The Chrome vulnerability

Google confirmed that the update addresses a single security issue in the web browser. The official release notes page reveals that it is a heap buffer overflow issue in the GPU. Google does not provide detailed information about vulnerabilities.

Without going into too many details, heap buffer overflow issues may lead to the execution of arbitrary code. Google confirms that the issue is exploited in the wild, which means that attacks take place at the time of writing.

The CVE-2022-4135 record lists additional information on the issue at hand:

“Heap buffer overflow in GPU in Google Chrome prior to 107.0.5304.121 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.”

The issue affects all old versions of the Chrome browser, both on the Stable and Extended Stable channel. The description highlights that the attack is web-based, using a specially crafted HTML page to exploit the issue. In other words: all it takes is to visit a webpage in Chrome to run the risk of being attacked successfully.

Google fixed 10 security issues in Chrome 107, which it released two weeks ago.

Other Chromium-based browsers

Brave Browser fully updated

The security issue affects all Chromium-based browsers; this includes Microsoft Edge, Brave, Vivaldi and Opera.

Only Brave Software, maker of the Brave Browser, released a security update for the browser so far. The company confirmed the release of the security update on its Twitter account.

Brave users may load brave://settings/help or select Brave Icon > Help > About Brave to display the current version. New updates are downloaded and installed automatically when the page is opened.

Author: Jesús Bosque

{ "de-DE": "Ich bin Journalist mit über 30 Jahren Erfahrung in Videospielen und Technologie. Obwohl Videospiele schon immer mein Fachgebiet waren, habe ich begonnen, auch die komplexen Strukturen von Projektmanagement-Tools wie Asana sowie die Automatisierungen mit Make.com und N8N zu entdecken und zu genießen.", "en-US": "I’m a journalist with more than 30 years of experience in video games and technology. Although my specialty has always been video games, I’ve recently started enjoying exploring the intricacies of project-management tools like Asana, as well as automations with Make.com and N8N.", "es-ES": "Soy periodista con más de 30 años de experiencia en videojuegos y tecnología. Aunque mi especialidad siempre ha sido el videojuego, he empezado a disfrutar también de descubrir los laberintos de los programas de project management como Asana y las automatizaciones de make.com y de N8N", "fr-FR": "Je suis journaliste avec plus de 30 ans d’expérience dans le jeu vidéo et la technologie. Bien que ma spécialité ait toujours été le jeu vidéo, j’ai commencé à prendre plaisir à explorer également les méandres des outils de gestion de projet comme Asana, ainsi que les automatisations avec Make.com et N8N.", "it-IT": "Sono un giornalista con oltre 30 anni di esperienza nei videogiochi e nella tecnologia. Anche se la mia specialità è sempre stata il videogame, ho iniziato a divertirmi anche a scoprire i meccanismi degli strumenti di project management come Asana e delle automazioni con Make.com e N8N.", "ja-JP": "", "nl-NL": "Ik ben een journalist met meer dan 30 jaar ervaring in videogames en technologie. Hoewel videogames altijd mijn specialiteit zijn geweest, ben ik ook begonnen te genieten van het verkennen van de ingewikkelde wereld van projectmanagementtools zoals Asana en van automatiseringen met Make.com en N8N.", "pl-PL": "Jestem dziennikarzem z ponad 30-letnim doświadczeniem w grach wideo i technologii. Choć moją specjalizacją zawsze były gry wideo, ostatnio zacząłem również czerpać przyjemność z odkrywania zawiłości narzędzi do zarządzania projektami, takich jak Asana, oraz automatyzacji w Make.com i N8N.", "pt-BR": "Sou jornalista com mais de 30 anos de experiência em videogames e tecnologia. Embora meu foco sempre tenha sido os videogames, recentemente passei a gostar de explorar também os labirintos de ferramentas de gestão de projetos como o Asana e das automações com Make.com e N8N.", "social": { "email": "jesus.bosque@softonic.com", "facebook": "", "twitter": "", "linkedin": "" } }