SecPod

Learn Search

Search across all Learn content

← Back to Security Research
Google Chrome Rolls out an Emergency Security Patch for a High Severity Zero-day vulnerability

Google Chrome Rolls out an Emergency Security Patch for a High Severity Zero-day vulnerability

Jun 6, 2023By Muqsit Mamdu2 min read

Google has recently released an emergency security fix to patch a Zero-day vulnerability in the Chrome web browser. Chrome Zero-day Vulnerability was found within Chrome’s V8 JavaScript engine. Google released the fix to patch this vulnerability on Monday (June 05, 2023). This Zero-day flaw exists in the wild, according to Google advisory. This is the third Zero-day vulnerability addressed by Google since the start of the year. Google tracked this Zero-day vulnerability as CVE-2023-3079 and assigned it a high severity rating. It is essential to have a vulnerability scanning tool to check for vulnerabilities from time to time. At the thought of publication, there were no known POCs available.

Chrome Zero-day Vulnerability Zero-Day CVE-2023-3079

Chrome’s V8 JavaScript Engine is affected by this vulnerability. V8 is a free and open-source JavaScript and WebAssembly engine developed by the Chromium Project for Chromium and Google Chrome web browsers. Here the vulnerability is exploited by a type-confusion flaw in the V8 JavaScript engine. Type Confusion vulnerability arises when the program allocates a particular type of resource to an object or a variable and then accesses a different type of resource. When there is a compatibility issue in the type of resource allocated, the confusion in this process leads to this kind of vulnerability. Clément Lecigne of Google’s Threat Analysis Group reported this vulnerability on 2023-06-01.

In its advisory, Google stresses the severity of this flaw by mentioning, 

“Google is aware that an exploit for CVE-2023-3079 exists in the wild.”

Affected Products Chrome Zero-day Vulnerability

Google Chrome version before 114.0.5735.106 for Mac and Linux and 114.0.5735.110 for Windows.

Impact

Type confusion in the V8 JavaScript Engine of Google Chrome could allow a remote attacker to exploit heap corruption via a crafted HTML page, leading to arbitrary code execution.

Solution

Google has rolled out security updates addressing the issue in Google Chrome version 114.0.5735.106 for Mac and Linux and 114.0.5735.110 for Windows. However, SanerNow detects and automatically fixes these vulnerabilities by applying security updates. Finally, use SanerNow to keep your systems updated and secure. We strongly recommend applying the security updates as soon as possible following the instructions published in our support article.

Featured Posts

Open Plex Releases Security Fixes for Media Server and Desktop Clients - Users Urged to Update Immediately
Plex Releases Security Fixes for Media Server and Desktop Clients - Users Urged to Update Immediately

CVE Research

Plex Releases Security Fixes for Media Server and Desktop Clients - Users Urged to Update Immediately

Plex has released security updates for Plex Media Server and Plex Desktop and is urging users to upgrade immediately. Plex Media Server v1.43.2 and earlier should be moved to version 1.43.3; Plex Desktop should be updated to 1.115.0. CVE identifiers have been requested, and full technical details are not public yet. This article covers the fixed versions, how to update across Windows, macOS, Linux, NAS, Docker, and other platforms, and what administrators should do now.

Sep 15, 2026

Open From Gitea Exploitation to Root Access: Uncovering Red Heron’s Global Attack Campaign
From Gitea Exploitation to Root Access: Uncovering Red Heron’s Global Attack Campaign

CVE Research

From Gitea Exploitation to Root Access: Uncovering Red Heron’s Global Attack Campaign

Sep 15, 2026

Open Active Exploitation Imminent: Two Critical Check Point Flaws (CVE-2026-85102, CVE-2026-85103) Allow Unauthenticated Remote Code Execution on VPN-Enabled Security Gateways and Management Appliances
Active Exploitation Imminent: Two Critical Check Point Flaws (CVE-2026-85102, CVE-2026-85103) Allow Unauthenticated Remote Code Execution on VPN-Enabled Security Gateways and Management Appliances

CVE Research

Active Exploitation Imminent: Two Critical Check Point Flaws (CVE-2026-85102, CVE-2026-85103) Allow Unauthenticated Remote Code Execution on VPN-Enabled Security Gateways and Management Appliances

CVE-2026-85102 and CVE-2026-85103 are critical vulnerabilities in Check Point VPN products that can allow unauthenticated remote code execution. The first flaw involves improper validation of certificate data during VPN negotiation on Security Gateways and Spark Firewalls using Site-to-Site or Remote Access VPN. The second is a heap overflow in ASN.1 certificate decoding that can affect Security Gateways, Security Management Servers, and Spark Firewalls. This article covers how the issues work, the affected products and versions, available LivePatch and Jumbo Hotfix fixes, and temporary Site-to-Site VPN mitigations.

Sep 15, 2026

Open Cisco FMC Zero-Day Under Active Attack: UAT-12197, UAT-11823 and Qilin-Linked UAT-11988 Exploit Firewall Flaws
Cisco FMC Zero-Day Under Active Attack: UAT-12197, UAT-11823 and Qilin-Linked UAT-11988 Exploit Firewall Flaws

CVE Research

Cisco FMC Zero-Day Under Active Attack: UAT-12197, UAT-11823 and Qilin-Linked UAT-11988 Exploit Firewall Flaws

Sep 11, 2026