A high-severity security advisory from Gentoo Linux has outlined multiple vulnerabilities in the core Chromium engine, creating an immediate, widespread risk for users of Google Chrome, Microsoft Edge, Opera, and Vivaldi. The urgent directive for all users and administrators is to manually update their web browsers without delay.

The flaws, detailed in advisory GLSA 202609-02 published on 12 September, affect the shared open-source codebase that powers a dominant portion of the world's browsing software. A vulnerability in this foundational layer creates a cascading threat, exposing a vast attack surface across several major commercial products.

For most users, the web browser is the primary gateway to the internet and a critical security checkpoint. Exploitation of such vulnerabilities often requires only a visit to a malicious or compromised website, making immediate patching essential to prevent potential remote code execution, data theft, or system compromise.

This event starkly illustrates the double-edged nature of collaborative software development. While the shared Chromium project enables rapid security and feature improvements across the ecosystem, it also means a single critical flaw can instantaneously compromise a huge segment of the global browser market.

Immediate Update Instructions

Because the vulnerabilities reside in the engine, each vendor must distribute its own patched version. Update mechanisms and timelines vary, so manual verification is critical. Users and IT teams must proactively check for and apply updates on all major operating systems.

For Google Chrome: * Click the three-dot menu in the top-right corner, navigate to Help > About Google Chrome. The browser will automatically check for updates and download the latest version. Click Relaunch to apply the update.

For Microsoft Edge: * Click the three-dot menu in the top-right corner, select Help and feedback > About Microsoft Edge. The browser will check for and install updates automatically. Restart the browser when prompted.

For Opera and Vivaldi: * Check for updates immediately via the browser's menu. The standard path is typically found under Menu > Help > About [Browser Name], where an update check will be initiated.

Organizations are strongly advised to ensure their update management policies are active and to consider issuing a direct alert to all staff. The systemic nature of the vulnerability means no Chromium-based browser can be considered secure until the update is deployed.

The Gentoo advisory serves as a definitive confirmation of the issue's severity. While technical specifics of each CVE are detailed within the advisory, the operational takeaway is unambiguous: active risk persists until the update is applied across all machines.

This incident underscores the interconnected nature of modern software security. A flaw in a single open-source component can rapidly escalate into a global event, necessitating swift, coordinated action from vendors and end-users alike.


Gentoo Linux發出一項高危保安通告,詳述了核心Chromium引擎中存在多個漏洞,令Google Chrome、Microsoft Edge、Opera及Vivaldi的用戶面臨即時且廣泛的風險。通告緊急指示所有用戶和管理員必須立即手動更新其網絡瀏覽器。

這些缺陷詳見於9月12日發布的安全通告GLSA 202609-02,影響了驅動全球大部分瀏覽軟件的共享開源代碼庫。這個基礎層面的漏洞產生連鎖威脅,令多款主要商業產品暴露於龐大的攻擊面之下。

對大多數用戶而言,網絡瀏覽器是進入互聯網的主要門戶和關鍵保安檢查點。利用此類漏洞通常只需造訪一個惡意或已被入侵的網站,因此立即進行修補對於防止潛在的遠端代碼執行、數據竊取或系統入侵至關重要。

此事件鮮明地揭示了協作軟件開發的雙刃劍性質。雖然共享的Chromium項目能促進整個生態系統的安全和功能快速提升,但也意味著一個關鍵缺陷可能瞬間危害全球瀏覽器市場的巨大部分。

立即更新指引

由於漏洞存在於引擎層面,每個供應商必須分發各自的修補版本。更新機制和時間表各異,因此手動驗證至關重要。用戶及IT團隊必須主動檢查並在所有主要操作系統上應用更新。

對於Google Chrome: * 按一下右上角的三點選單,導覽至「說明 > 關於Google Chrome」。瀏覽器會自動檢查更新並下載最新版本。按一下「重新啟動」以套用更新。

對於Microsoft Edge: * 按一下右上角的三點選單,選取「說明與意見回饋 > 關於Microsoft Edge」。瀏覽器會自動檢查並安裝更新。當提示時,請重啟瀏覽器。

對於Opera及Vivaldi: * 請立即透過瀏覽器選單檢查更新。標準路徑通常可在「選單 > 說明 > 關於 [瀏覽器名稱]」下找到,此處將啟動更新檢查。

強烈建議各組織確保其更新管理政策處於啟用狀態,並考慮向所有員工發出直接提醒。此漏洞的系統性特質意味著,在更新部署至所有機器之前,任何基於Chromium的瀏覽器都不能被視為安全。

Gentoo的通告確鑿地證實了該問題的嚴重性。雖然每個CVE的技術細節已在通告中詳述,但操作層面的結論明確無誤:在所有機器套用更新之前,風險依然存在。

此事件突顯了現代軟件保安的互聯本質。一個開源組件中的缺陷可迅速升級為全球性事件,需要供應商和最終用戶雙方迅速採取協調行動。

新聞來源 / Original News Source