Google has updated Chrome to fix 14 security flaws, including one "zero-day" flaw that's actively being exploited by hackers unknown.
To make sure your desktop version of Chrome for Windows or Mac is updated to version 91.0.4472.101, click the three vertical dots at the top right of the browser window, scroll down to Help, and then click on "About Google Chrome" in the fly-out menu.
A new tab will open. If it tells you your browser is up-to-date, you're done. If not, it will automatically download the new version, after which you have to relaunch the browser. (Linux users may have to wait for their distribution's next update.)
- Microsoft fixes six zero-day flaws in Windows 10 — update right now
- The best Windows 10 antivirus software
- Plus: How to watch In the Heights online or in theaters
The zero-day, catalogued as CVE-2021-30551, is related to a Windows flaw, also a zero-day, that Google researchers discovered last week and Microsoft patched yesterday (June 8). That's according to Shane Huntley, director of Google's Threat Analysis Group.
Chrome in-the-wild vulnerability CVE-2021-30551 patched today was also from the same actor and targeting.Thanks to Chrome team for also patching within 7 days.https://t.co/1RDbbuiBfY https://t.co/Ap9dEq98CyJune 9, 2021
None of those other four browsers had incorporated the Chrome patch at the time of this writing Wednesday evening Eastern time, but we'll show you how to check at the end of this piece.
It's not clear how technically similar the Chrome and Microsoft zero-days are. The Microsoft one affects HTML parsing used in Internet Explorer and other legacy software, but that software is used by the Chromium-based Edge only when in "Internet Explorer mode."
Bleeping Computer noted that this is the sixth Chrome zero-day flaw patched so far in 2021. Two patched by Google in April were used in conjunction with two Microsoft flaws discovered by Kaspersky and patched by Microsoft yesterday (June 8).
All of these zero-day flaws seem to have been used in sophisticated nation-state attacks against specific targets, presumably for espionage purposes. But as details leak out about the flaws, criminals may start using them for more indiscriminate attacks against a wider range of targets.
The security risk of today's Chrome zero-day is rated "High." However, there's another fix for a flaw marked "Critical" that involves "use after free in BFCache," which means that a vulnerability exists in the way Chrome holds recently viewed web pages in a computer's running memory.
How to check if Edge, Brave, Opera or Vivaldi are up to date with Chrome
Here's a list of the most recent Chrome/Chromium updates.
- June 9: 91.0.4472.101
- May 25: 91.0.4472.77
- May 10: 90.0.4430.212
- April 26: 90.0.4430.93
- April 20: 90.0.4430.85
- April 14: 90.0.4430.72
- April 13: 89.0.4389.128
- March 30: 89.0.4389.114
- March 12: 89.0.4389.90
- March 5: 89.0.4389.82
- March 2: 89.0.4389.72
Among other Chromium browsers, Brave uses Chrome's version numbers, so it's easy to see whether it's up to date.
In Edge, you have to type "edge://version" into the address bar and hit Enter or Return. In the resulting page, "User agent" will tell you the corresponding version of Chrome. Edge and Brave can be updated the same way as Chrome.
In Opera and Vivaldi, click the browser icon in the top left corner, then Help > About. Under "User Agent" or "Browser Identification," you'll see the corresponding Chrome version number.
In Opera, that page will also trigger an update if one is available; in Vivaldi, you click Help > Check for Updates.