Google has released an emergency security update for its Chrome browser, addressing a high-severity zero-day vulnerability that is already being actively exploited by attackers. This marks the seventh zero-day flaw patched in Chrome since the beginning of 2026, reinforcing the stark reality that web browsers remain a prime target for malicious actors.
The vulnerability, tracked as CVE-2024-4761, resides in Chrome's V8 JavaScript engine and is classified as a "type confusion" flaw. Attackers can exploit it by crafting malicious web content that triggers remote code execution, potentially granting them full control over affected devices. Google has confirmed that exploitation of this vulnerability is occurring in the wild.
Google's security response team moved swiftly, delivering a fix within 48 hours of the vulnerability being disclosed. The patch arrived as part of a larger security update that addressed a total of 230 vulnerabilities, with CVE-2024-4761 singled out due to its critical severity. This rapid turnaround underscores the relentless security demands faced by those maintaining major browser projects.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2024-4761 to its Known Exploited Vulnerabilities catalog. Inclusion in the KEV catalog signals the highest tier of risk and typically mandates remediation deadlines for federal agencies, while serving as a strong directive for all organizations to prioritize the fix.
The frequency of zero-day patches in Chrome this year is notable — the browser has averaged roughly one actively exploited zero-day fix per month in 2026. This pattern highlights that browsers continue to be a focal point for sophisticated threat groups.
The guidance for all users and IT administrators is unambiguous: update all Chrome installations immediately to version 124.0.6367.207/208 or later. Applying this patch before the vulnerability is widely weaponized remains the most effective defense against this threat.
Google 已為其 Chrome 瀏覽器發布緊急安全更新,修補一個正被攻擊者積極利用的高危零日漏洞。這標誌著自 2026 年初以來,Chrome 已修補第七個零日漏洞,再次印證了一個嚴峻事實:網頁瀏覽器仍是惡意行為者的首要攻擊目標。
該漏洞追蹤編號為 CVE-2024-4761,存在於 Chrome 的 V8 JavaScript 引擎中,被歸類為「類型混淆」缺陷。攻擊者可透過構造惡意網頁內容利用此漏洞觸發遠端程式碼執行,從而可能完全控制受影響的設備。Google 已確認該漏洞正被積極利用。
Google 安全回應團隊迅速行動,在漏洞披露後 48 小時內即提供了修復方案。該 patch 是涵蓋總共 230 個漏洞的大型安全更新的一部分,其中 CVE-2024-4761 因其嚴重性而被單獨強調。這種快速的回應凸顯了維護主要瀏覽器項目所面臨的持續性安全壓力。
美國網絡安全與基礎設施安全局 (CISA) 已將 CVE-2024-4761 納入其已知被利用漏洞目錄。列入該目錄的信號代表最高風險等級,通常會為聯邦機構設定強制修復期限,同時也向所有組織發出優先處理此 patch 的強烈指示。
今年 Chrome 修補零日漏洞的頻率引人注目——該瀏覽器在 2026 年平均每月修補約一個積極利用的零日漏洞。此模式表明,瀏覽器持續成為複雜威脅組織的焦點目標。
給所有用戶和 IT 管理員的指引非常明確:立即將所有 Chrome 安裝版本更新至 124.0.6367.207/208 或更高版本。在該漏洞被大規模武器化之前應用此 patch,仍是對抗此威脅的最有效防禦措施。
