Google has implemented fixes for 42 vulnerabilities in the Chrome browser, three of which were classified as critical. The company itself stated that none of these flaws have been exploited in cyberattacks so far.
Of the detected vulnerabilities, 26 were identified internally by the Google team, while the remaining 16 were discovered by external researchers.
To prevent attackers from taking advantage of these security gaps, Google has already released a comprehensive security update for Windows, macOS, Linux, Android, and iOS operating systems.
The solutions for the vulnerabilities are contained in Chrome builds 153.0.8010.47 and 153.0.8010.48 for Windows and macOS, as well as version 153.0.8010.47 for Linux and Android. iOS users also received protections through browser version 154.0.8037.41.
In practical terms, the three most serious flaws could allow an attacker to escape the browser's isolated environment, known as the sandbox, and operate directly on the victim's operating system. The method to exploit such vulnerabilities would only require the user to access a manipulated webpage.
In addition to the critical fixes, the update also addresses 28 high-risk flaws, along with several other medium and low-severity issues. Among the adjustments made, security improvements applied to the JavaScript engine and the Chrome extensions system stand out.
Although Chrome usually downloads these improvements in the background, the distribution process occurs progressively. To ensure immediate protection, users have the option to force the update manually. Guides are available to assist with the Google Chrome update procedure on Android, iPhone, and PC. In the case of Linux, the availability of the update may vary depending on the distribution, such as Fedora and Ubuntu, where management is done via the package installer, not the internal browser menu.
It is important to note that Google has adopted a policy of releasing a new Chrome version every two weeks, aiming to strengthen security and expedite the delivery of improvements to users.
