The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has ordered federal agencies to urgently patch a critical Google Chrome vulnerability, marking the seventh time this year the browser maker has been forced to fix a zero-day flaw already under active attack.

Google's latest security update, which addresses 230 vulnerabilities, includes a critical fix for CVE-2024-40711. This flaw is the seventh actively exploited Chrome zero-day patched in 2024, an unprecedented pace that underscores a relentless focus by attackers on browsers as a primary intrusion vector. A zero-day is a software vulnerability unknown to the vendor, meaning attackers can exploit it before a defensive patch exists.

While Google withholds many technical details to protect users during the update rollout, it confirmed the bug's high severity. The critical patch arrives in Chrome version 128.0.6613.113/114 for Windows and Mac, and version 128.0.6613.113 for Linux.

The immediate action required is driven by a federal mandate. CISA has added CVE-2024-40711 to its Known Exploited Vulnerabilities (KEV) catalog, triggering a binding directive for all Federal Civilian Executive Branch (FCEB) agencies to remediate the flaw by a specified deadline. While legally binding only for federal entities, this directive serves as a definitive, high-stakes advisory to all organizations globally: exploitation is active and confirmed.

The seven zero-day discoveries this year before autumn signal a historic and sustained assault on browser security. This trend reflects both escalating adversary sophistication and the inherent complexity of securing modern web software, placing immense pressure on developers and administrators alike.

For IT administrators and individual users, the response is non-negotiable: immediate patching is mandatory. The frequency of these incidents transforms standard security advice into a critical operational imperative.

Immediate Steps for Individual Users: 1. Check for the Update: Open Chrome, go to the three-dot menu > Help > About Google Chrome. 2. Install the Patch: The browser will automatically download the latest version. Click the "Relaunch" button when it appears. 3. Confirm the Version: Ensure your browser is running version 128.0.6613.113 or higher.

For IT Administrators: - Prioritize Deployment: Use endpoint management tools to push Chrome version 128.0.6613.113+ to all corporate devices without delay. - Audit for Compliance: Verify that all browser instances across the network have been updated, leaving no vulnerable systems exposed. - Implement Mitigations: For devices that cannot be immediately patched, consider enforcing strict web content filtering or restricting sensitive online activity as a temporary safeguard.

This seventh zero-day fix of the year is a stark indicator of an evolving threat landscape. Maintaining up-to-date software is no longer a best practice but a fundamental, non-negotiable component of basic cyber defense.


美國網絡安全和基礎設施安全局(CISA)已勒令聯邦機構緊急修補一個 Google Chrome 關鍵漏洞,這是今年以來第七次迫使該瀏覽器製造商修補已被主動利用的零日漏洞。

Google 最新的安全更新修補了 230 個漏洞,其中包括針對 CVE-2024-40711 的關鍵修復。這個漏洞是 2024 年第七個被主動利用的 Chrome 零日漏洞,其前所未見的修補速度突顯了攻擊者持續將瀏覽器作為主要入侵媒介的堅決態勢。零日漏洞是軟件供應商未知的漏洞,意味著防禦補丁出台前攻擊者便可加以利用。

雖然 Google 為保護用戶在更新推出期間隱去了許多技術細節,但證實了該漏洞的嚴重程度極高。此次關鍵補丁已隨 Chrome 版本 128.0.6613.113/114(Windows 及 Mac 版本)以及 128.0.6613.113(Linux 版本)推出。

立即行動的要求源於聯邦指令。CISA 已將 CVE-2024-40711 納入其已知被利用漏洞(KEV)目錄,觸發了要求所有聯邦民事行政分支(FCEB)機構須在指定期限前修補此漏洞的強制性指令。儘管此指令僅對聯邦實體具法律約束力,但其向全球所有組織傳遞了明確且高風險的警示:漏洞利用現況活躍且已獲證實。

今年秋季前的七次零日漏洞發現,標誌著對瀏覽器安全持續而歷史性的攻擊。此趨勢反映了攻擊方日益複雜的技術,以及保障現代網絡軟件安全所固有的複雜性,令開發人員與管理員均承受巨大壓力。

對 IT 管理員及個人用戶而言,回應措施不容有失:立即安裝補丁乃強制要求。這類事件發生的頻率,已將常規安全建議轉化為關鍵的操作指令。

個人用戶立即步驟: 1. 檢查更新: 開啟 Chrome,前往三點選單 > 說明 > 關於 Google Chrome。 2. 安裝補丁: 瀏覽器將自動下載最新版本。出現後請點擊「重新啟動」按鈕。 3. 確認版本: 確保您的瀏覽器運行版本為 128.0.6613.113 或更高。

IT 管理員注意事項: - 優先部署: 使用端點管理工具立即向所有公司設備推送 Chrome 版本 128.0.6613.113 或以上版本。 - 合規審計: 確認網絡中所有瀏覽器實例均已更新,不留任何易受攻擊系統暴露。 - 實施緩解措施: 對於無法立即修補的設備,請考慮強制執行嚴格的網絡內容過濾或限制敏感在線活動,作為臨時安全防護。

今年第七次零日漏洞修補事件,明確顯示了威脅環境的演變態勢。保持軟件最新狀態,已不再是最佳實踐,而是基礎網絡防禦中不可或缺且不容妥協的組成部分。

新聞來源 / Original News Source