Google has released an emergency security update for Chrome, patching a newly discovered zero-day vulnerability already under active attack. This marks the seventh such critical flaw in Chrome exploited by hackers since the beginning of 2024.

The update, deployed globally on Tuesday, fixes a total of 230 vulnerabilities. While most are standard patches, the inclusion of an actively exploited zero-day makes this update critical for all users. A zero-day is a security flaw unknown to the vendor or one for which no patch yet exists, granting attackers a window of opportunity. The fact that seven such Chrome vulnerabilities have been discovered and patched in just over five months signals a significant and concerning escalation in threats targeting the world's dominant web browser.

According to a report from BleepingComputer, the update addresses this new zero-day along with several other high-severity issues. Google is withholding specific technical details to avoid assisting potential attackers. However, its "actively exploited" classification confirms that threat actors have already developed methods to leverage it, likely for unauthorized code execution or data theft. This reality underscores the relentless arms race between software developers and malicious actors.

This frequency of zero-day discoveries—seven in less than half a year—is a significant trend. It suggests either a major increase in adversary focus on browser exploitation or more intense scrutiny revealing deeper flaws. In either case, it reinforces that browsers remain a primary cybersecurity battleground. For IT and security teams, the rhythm of emergency, out-of-cycle browser patches must now be treated as a standard component of operational risk management.

Immediate Action Required

Given the confirmed risk, all users and administrators are urged to apply this update immediately. While Chrome's auto-update mechanism should deploy it, manual verification is recommended.

To manually update Google Chrome: 1. Open the Chrome browser. 2. Click the three vertical dots in the top-right corner. 3. Navigate to Help > About Google Chrome. 4. The browser will check for and download the latest version. 5. Click Relaunch to complete the update.

IT administrators managing device fleets should prioritize accelerating the deployment of this update across all managed endpoints. Reviewing browser logs for anomalous activity on any devices not yet updated is a prudent supplementary step.

This latest patch is a stark reminder that maintaining up-to-date software is a critical defensive imperative. For Hong Kong's IT professionals, treating this update as a top-priority task is essential to mitigate immediate risk.


Google 已為 Chrome 發布緊急安全更新,修補一個新發現且正遭受積極利用的零日漏洞。這是自2024年初以來,Chrome 中被駭客利用的第七個此類嚴重漏洞。

該更新已於週二在全球部署,共修補了230個漏洞。雖然大多數是標準修補,但由於包含一個正遭積極利用的零日漏洞,這次更新對所有用戶都至關重要。零日漏洞是指軟體供應商尚未知曉或尚未有可用修補程式的安全缺陷,這讓攻擊者有可乘之機。在短短五個多月內就發現並修補了七個此類 Chrome 漏洞,這是一個顯著且令人擔憂的威脅升級信號,針對的是全球主導的網絡瀏覽器。

根據 BleepingComputer 的報導,本次更新處理了這個新的零日漏洞以及數個其他高嚴重性問題。Google 暫未提供具體技術細節,以避免協助潛在攻擊者。然而,其「正遭積極利用」的分類證實,威脅行為者已開發出利用此漏洞的方法,很可能用於未授權的代碼執行或數據盜竊。這一現實凸顯了軟件開發者與惡意行為者之間持續不斷的軍備競賽。

如此頻繁地發現零日漏洞——半年內七次——是一個重要趨勢。這表明對手對瀏覽器漏洞利用的關注度大幅增加,或是更嚴格的審查揭示了更深層的缺陷。無論是哪種情況,都再次強調瀏覽器仍是網絡安全的主要戰場。對於 IT 和安全團隊而言,瀏覽器緊急、非週期性更新的節奏,現在必須被視為運營風險管理的標準組成部分。

需立即採取行動

鑒於已確認的風險,敦促所有用戶和管理員立即應用此更新。雖然 Chrome 的自動更新機制應會部署它,但建議手動驗證。

手動更新 Google Chrome 的方法: 1. 打開 Chrome 瀏覽器。 2. 點擊右上角的三個垂直圓點。 3. 前往 說明 > 關於 Google Chrome。 4. 瀏覽器將會檢查並下載最新版本。 5. 點擊 重新啟動 以完成更新。

管理設備群組的 IT 管理員應優先加速在所有受管端點部署此次更新。對於尚未更新的設備,檢查瀏覽器日誌是否有異常活動是謹慎的補充步驟。

最新的這份更新是一個鮮明提醒,維持軟件最新狀態是一項至關重要的防禦要求。對於香港的 IT 專業人員而言,將此更新視為高優先級任務,對於減輕即時風險至關重要。

新聞來源 / Original News Source