Google yesterday released the new Chrome version 86.0.4240.111 , with security updates , to fix a zero-day vulnerability that, according to the company, is already being used cybercriminals by .

The zero-day vulnerability has been named “ CVE-2020-15999 ” by researchers and is described as a memory-impacting bug in the FreeType font rendering library, which is present in standard Chrome distributions.
Security researchers at Project Zero (Google's internal security team) have identified attacks that exploit a zero-day vulnerability in FreeType.
According to Project Zero team leader Ben Hawkes, there is at least one hacking group exploiting this bug to target users Chrome.
Hawkes also urges vendors of other applications that use the same FreeType library to update their software as well, as attackers may decide to shift attacks and target other applications. That's why Google released FreeType 2.10.4to help vendors patch the vulnerability.

As for Chrome users , they can get the new version v86.0.4240.111 through the browser's built-in update function (go to the Chrome menu, click "Help" and go to the "About Google Chrome" section).
No further details have been released about the zero-day vulnerability CVE-2020-15999 at this time. Google typically avoids releasing technical details for months to give users enough time to update their systems without risking attacks ( as far as the company can).
However, since the patch for the zero-day vulnerability is visible in the source code of FreeType (an open source project), attackers could reverse-engineer and find their own exploits in the coming days or weeks.
According to ZDNet, the CVE-2020-15999 vulnerability is the third zero-day in Google Chrome to be exploited by hackers in the past year. The previous two were CVE-2019-13720 (October 2019) and CVE-2020-6418 (February 2020).
