Google has patched two zero-day vulnerabilities in its Chrome browser, the third time in two weeks that the company has fixed a Chrome security flaw that’s under active exploit.
Hawkes didn’t provide additional details, such as what desktop versions of Chrome were actively targeted, who the victims were, or how long the attacks had been going on. It also wasn’t clear if the same attack group was responsible for all three exploits. CVE-2020-16009 was in part discovered by a member of Google’s Threat Analysis Group, which focuses on government-backed hacking, suggesting that exploits of that vulnerability may be the work of a nation-state. Project Zero was involved in the discovery of all three of the zero-days.
The updates come two weeks after Google fixed CVE-2020-15999, an actively exploited vulnerability in Freetype, which Chrome and other, non-Google apps use to render fonts. To gain code-execution capabilities, hackers were combining exploits with a separate one that targeted currently unpatched bug in Windows 10 and Windows 7.
Desktop versions of Chrome typically update automatically. That means that, for most users, patches for CVE-2020-16009 and CVE-2020-15999 have already been installed, as long as they’ve recently restarted their browser. Chrome for Android is updated through Google Play. The Chrome Android advisory said the fix is incorporated into version 86.0.4240.185. The notice went on to say the update would be available “over the next few weeks,” but the phone I checked (a Pixel) already had it installed.