SecPod

Learn Search

Search across all Learn content

← Back to Security Research
Chrome Zero-Day Under Active Exploitation – Patch Now

Chrome Zero-Day Under Active Exploitation – Patch Now

We all know the popularity and extensive audience of the Google Chrome browser, which can be used on Windows, Mac, or Linux computers and Android devices. To those currently using the same and who have not yet deployed the patch, it’s time to update their Chrome browsers to the latest version, 86.0....

Oct 21, 2020By Vishesh S3 min read

We all know the popularity and extensive audience of the Google Chrome browser, which can be used on Windows, Mac, or Linux computers and Android devices. To those currently using the same and who have not yet deployed the patch, it’s time to update their Chrome browsers to the latest version, 86.0.4240.111 Google released. The latest version of Google Chrome Zero-Day Oct 2020 has addressed a serious 0-day heap buffer overflow vulnerability and three high-risk and medium-risk vulnerabilities. A good vulnerability management tool can prevent these attacks.

Zero-Day CVE-2020-15999 :

Chrome Zero-Day Oct 2020 actively exploited a memory corruption flaw, resulting in a heap buffer overflow in FreeType open-source development library used for rendering fonts packed with Chrome. These vulnerabilities can be kept at bay with a vulnerability management software. The vulnerability report by security researcher Sergei Glazunov of Google Project Zero on October 19. The security researcher then immediately reported the 0-day vulnerability to Freetype developers, who seemed to have addressed the issue in Freetype on October 20 with the release of FreeType 2.10.4.

According to the details shared by the reporter, the heap buffer overflow vulnerability. exists in the FreeType’s function “Load_SBit_Png” that processes PNG images embedded into fonts. This can be in exploitation by attackers to execute arbitrary code by using specially crafted fonts with embedded PNG images.

Glazunov explained,

The issue is that libpng uses the original 32-bit values, which are saved in `png_struct`. Therefore, if the original width and/or height are greater than 65535, the allocated buffer won’t be able to fit the bitmap.

The technical lead for Google’s Project Zero is Ben Hawkes. informed us that while they have only spotted the exploits targeting Chrome users. It is also possible that other projects using Freetype might also be vulnerable. They are advising to deploy the patch with FreeType version 2.10.4.

Since the patch for the vulnerability is visible in the source code of the FreeType open-source library. Attackers might be able to reverse-engineer the code and develop working exploits for this vulnerability.

Affected products by Chrome Zero-Day Oct 2020:

Google Chrome versions before 86.0.4240.111 and FreeType open-source library versions before 2.10.4.

Impact

This issue allows attackers to execute arbitrary code on the affected system.

Solution

Google has released security updates addressing the issue in Google Chrome version 86.0.4240.111.

SanerNow detects this vulnerability and automatically fixes it by applying security updates. Therefore, Download SanerNow and keep your systems updated and secure.

Featured Posts

Open Squidbleed: A 29-Year-Old Squid Proxy Flaw That Leaks Cleartext HTTP Requests
Squidbleed: A 29-Year-Old Squid Proxy Flaw That Leaks Cleartext HTTP Requests

CVE Research

Squidbleed: A 29-Year-Old Squid Proxy Flaw That Leaks Cleartext HTTP Requests

Jun 23, 2026

Open AryStinger Malware Leverages 4,300+ Legacy Routers to Establish Persistent Spy Infrastructure
AryStinger Malware Leverages 4,300+ Legacy Routers to Establish Persistent Spy Infrastructure

CVE Research

AryStinger Malware Leverages 4,300+ Legacy Routers to Establish Persistent Spy Infrastructure

AryStinger represents a calculated shift in IoT threat methodology, abandoning noisy, destructive payloads in favor of silent, long-term reconnaissance infrastructure. By exploiting unpatched, end-of-life routers and NAS devices through decade-old vulnerabilities, the threat operator has assembled a distributed fleet of over 4,300 Executor nodes capable of conducting parallelized DNS enumeration, port scanning, and service fingerprinting at scale, all while masking origin behind residential IP addresses. With active development ongoing and a potential operational timeline stretching back to 2024, AryStinger underscores a growing and underappreciated risk: forgotten edge hardware is not merely a compliance gap but exploitable infrastructure.

Jun 23, 2026

Open From Emergence to Dominance: INC Ransomware Surpasses 830 Victims and Strengthens Its RaaS Operations
From Emergence to Dominance: INC Ransomware Surpasses 830 Victims and Strengthens Its RaaS Operations

CVE Research

From Emergence to Dominance: INC Ransomware Surpasses 830 Victims and Strengthens Its RaaS Operations

INC Ransomware has rapidly evolved into one of the most active ransomware-as-a-service (RaaS) operations in 2026, claiming responsibility for more than 830 victims worldwide since its emergence in August 2023. Security researchers attribute its growth to a combination of aggressive affiliate recruitment, opportunistic targeting, and the disruption of major ransomware groups such as ALPHV/BlackCat and LockBit, which created opportunities for newer actors to expand their influence within the cybercrime ecosystem.

Jun 19, 2026

Open AI Assisted CTF: Same Systems. Two Scans. Before and After Saner
AI attack surface reduction using Saner

CVE Research

AI Assisted CTF: Same Systems. Two Scans. Before and After Saner

What changed when AI tested the lab before and after Saner reduced the usable attack surface

Jun 12, 2026

Chrome Zero-Day Under Active Exploitation – Patch Now | SecPod