SecPod

Learn Search

Search across all Learn content

← Back to Security Research
Google Chrome Rolls out an Emergency Security Patch for a High Severity Zero-day vulnerability

Google Chrome Rolls out an Emergency Security Patch for a High Severity Zero-day vulnerability

Jun 6, 2023By Muqsit Mamdu2 min read

Google has recently released an emergency security fix to patch a Zero-day vulnerability in the Chrome web browser. Chrome Zero-day Vulnerability was found within Chrome’s V8 JavaScript engine. Google released the fix to patch this vulnerability on Monday (June 05, 2023). This Zero-day flaw exists in the wild, according to Google advisory. This is the third Zero-day vulnerability addressed by Google since the start of the year. Google tracked this Zero-day vulnerability as CVE-2023-3079 and assigned it a high severity rating. It is essential to have a vulnerability scanning tool to check for vulnerabilities from time to time. At the thought of publication, there were no known POCs available.

Chrome Zero-day Vulnerability Zero-Day CVE-2023-3079

Chrome’s V8 JavaScript Engine is affected by this vulnerability. V8 is a free and open-source JavaScript and WebAssembly engine developed by the Chromium Project for Chromium and Google Chrome web browsers. Here the vulnerability is exploited by a type-confusion flaw in the V8 JavaScript engine. Type Confusion vulnerability arises when the program allocates a particular type of resource to an object or a variable and then accesses a different type of resource. When there is a compatibility issue in the type of resource allocated, the confusion in this process leads to this kind of vulnerability. Clément Lecigne of Google’s Threat Analysis Group reported this vulnerability on 2023-06-01.

In its advisory, Google stresses the severity of this flaw by mentioning, 

“Google is aware that an exploit for CVE-2023-3079 exists in the wild.”

Affected Products Chrome Zero-day Vulnerability

Google Chrome version before 114.0.5735.106 for Mac and Linux and 114.0.5735.110 for Windows.

Impact

Type confusion in the V8 JavaScript Engine of Google Chrome could allow a remote attacker to exploit heap corruption via a crafted HTML page, leading to arbitrary code execution.

Solution

Google has rolled out security updates addressing the issue in Google Chrome version 114.0.5735.106 for Mac and Linux and 114.0.5735.110 for Windows. However, SanerNow detects and automatically fixes these vulnerabilities by applying security updates. Finally, use SanerNow to keep your systems updated and secure. We strongly recommend applying the security updates as soon as possible following the instructions published in our support article.

Featured Posts

Open CVE-2023-49105: The ownCloud Authentication Flaw That Exposed Sensitive Credentials
CVE-2023-49105: The ownCloud Authentication Flaw That Exposed Sensitive Credentials

CVE Research

CVE-2023-49105: The ownCloud Authentication Flaw That Exposed Sensitive Credentials

Sep 25, 2026

Open Patch Analysis & Exploitation Timeline: RouterOS SSH Attacks Predate Production Fixes in CISA's September 10, 2026 KEV Additions
Patch Analysis & Exploitation Timeline: RouterOS SSH Attacks Predate Production Fixes in CISA's September 10, 2026 KEV Additions

CVE Research

Patch Analysis & Exploitation Timeline: RouterOS SSH Attacks Predate Production Fixes in CISA's September 10, 2026 KEV Additions

Two MikroTik RouterOS CVEs entered CISA KEV seven days after production fixes. Dated reporting places SSH-chain exploitation involving CVE-2026-86060 at least one calendar day before those releases; no comparable start date is established for CVE-2026-67277.

Sep 25, 2026

Open Patch Analysis & Exploitation Timeline: A Day-Old Chrome Bug and an Eight-Month-Old Fortinet Flaw Share the Same KEV Batch
Patch Analysis & Exploitation Timeline: A Day-Old Chrome Bug and an Eight-Month-Old Fortinet Flaw Share the Same KEV Batch

CVE Research

Patch Analysis & Exploitation Timeline: A Day-Old Chrome Bug and an Eight-Month-Old Fortinet Flaw Share the Same KEV Batch

Four vulnerabilities added to CISA’s KEV catalog on September 9, 2026 show widely different timelines between public disclosure and formal exploitation-based prioritization, ranging from one day to 239 days.

Sep 24, 2026

Open TA412/APT31: Mapping Threat Actor Patterns to CVE Exploitation Chains

TA412/APT31: Mapping Threat Actor Patterns to CVE Exploitation Chains

CVE Research

TA412/APT31: Mapping Threat Actor Patterns to CVE Exploitation Chains

A chronological look at how a long-running China-nexus espionage cluster evolved from server-side exploitation to a chained Chrome/Windows zero-day kit — and what that shift signals.

Sep 24, 2026