Google today released an updated version of Chrome to address three security bugs, including a zero-day vulnerability.
Details about these attacks are not yet public, and we don't know how this bug is being used against Chrome users.
All we know is that the attacks were discovered last week, on February 18, by Clement Lecigne, a member of Google's Threat Analysis Team, a division of Google that investigates and monitors threat groups.
Patches for this zero-day vulnerability have been released as part of Chrome version 80.0.3987.122. The update is available for Windows, Mac , and Linux, but not Chrome OS, iOS, and Android.
The zero-day vulnerability is listed as CVE-2020-6418 and is described only as “type confusion in V8.”.

V8 is the component of Chrome that is responsible for processing JavaScript code.
Type confusion refers to coding errors in which an application initializes data execution functions using input of a specific “type”, but is tricked into treating the input as a different “type”.
“Type confusion” leads to logical errors in the application's memory and can lead to situations in which an attacker can execute unrestricted malicious code within an application.

This is the third Chrome zero-day to appear in the past year.
Google patched the Chrome zero-day vulnerability in March of last year (CVE-2019-5786 in Chrome 72.0.3626.121) and then a second one appeared in November (CVE-2019-13720 in Chrome 78.0.3904.8).
We'll keep you updated if Google shares more information about the recent attacks. In the meantime, users are advised to update Chrome as soon as possible.
Chrome v80.0.3987.122 also comes with two additional security updates.
