Google has released a security update for its Chrome browser to fix a critical vulnerability already being actively exploited by attackers. This marks the seventh zero-day flaw the company has patched in Chrome since the start of 2024, underscoring the persistent targeting of the world's most popular web browser.

Reported by BleepingComputer, the security update, deployed on Tuesday, resolves a total of 230 vulnerabilities. Among these is the critical flaw, tracked as CVE-2024-2398, which Google confirmed was exploited in the wild. Zero-day vulnerabilities are particularly dangerous as they are unknown to the software vendor, offering no prior patch for defenders to deploy.

The update is being rolled out across desktop platforms, including Windows, Mac, and Linux. Users are typically prompted to restart the browser to apply the fix, but IT administrators should prioritize verifying the update's installation across managed fleets.

This latest incident continues a notable trend for 2024, making it the seventh such critical flaw exploited before a patch was available. The frequency underscores the immense pressure on browser security teams and the high-value target that Chrome represents for threat actors.

For IT teams, the immediate operational priority is clear: ensure all Chrome instances are updated to the patched version without delay. Given the confirmed active exploitation, unpatched systems are at direct risk of compromise. Organizations should confirm the version number via Chrome's "About Google" page, checking for the latest build incorporating the fix for CVE-2024-2398.

While the original report did not detail specific attack campaigns or threat actors, the pattern of repeated zero-days this year serves as a stark reminder of the evolving threat landscape. Enterprises and individual users alike must treat browser updates as critical security patches rather than optional software refreshes. The persistent targeting of Chrome emphasizes that maintaining a security perimeter now requires rigorous and swift patch management for foundational internet software.


Google 已為其 Chrome 瀏覽器發布安全更新,以修補一個正被攻擊者利用的重大漏洞。這標誌著自 2024 年初以來,該公司在 Chrome 中修補的第七個零日漏洞,突顯了這款全球最受歡迎的網頁瀏覽器持續成為攻擊目標。

據 BleepingComputer 報導,於週二部署的安全更新共解決了 230 個漏洞,其中包括編號為 CVE-2024-2398 的重大漏洞,Google 已證實該漏洞在野外被利用。零日漏洞尤為危險,因為它們對軟件供應商而言是未知的,防禦者沒有任何現成的補丁可以部署。

該更新正陸續推出至桌面平台,包括 Windows、Mac 和 Linux。用戶通常會被提示重啟瀏覽器以套用修正,但 IT 管理員應優先驗證受管理裝置群是否已安裝更新。

這次最新事件延續了 2024 年的一個顯著趨勢,使其成為第七個在補丁發布前就已被利用的重大漏洞。其頻率凸顯了瀏覽器安全團隊承受的巨大壓力,以及 Chrome 作為高價值目標對攻擊者的吸引力。

對 IT 團隊而言,當務之急的操作優先級很明確:確保所有 Chrome 實例毫不延遲地更新到已修補的版本。鑑於已證實的利用情況,未修補的系統面臨被直接入侵的風險。組織應透過 Chrome 的「關於 Google」頁面確認版本號,檢查是否包含針對 CVE-2024-2398 修復的最新版本。

雖然最初的報告並未詳細說明具體的攻擊活動或威脅者,但今年反覆出現的零日漏洞模式,強烈提醒人們威脅環境的演變。企業和個人用戶都必須將瀏覽器更新視為關鍵的安全補丁,而非可選的軟件刷新。Chrome 持續成為攻擊目標,強調了維護安全邊界現在需要對基礎互聯網軟件進行嚴格且迅速的補丁管理。

新聞來源 / Original News Source