The latest security update released by Google for its Chrome web browser fixes ten bugs, including a zero-day vulnerability that was previously exploited by malicious users.

The vulnerability has been designated as CVE-2020-16009 and was discovered by the Google Threat Analysis Group (TAG), a security team at the company that is tasked with monitoring threat actors and their activities.
As is Google's custom, details about the vulnerability and the group exploiting the bug have not been made public. This gives Chrome users more time to install updates, while other threat actors do not have the opportunity to discover other ways to exploit the vulnerability.
However, in a brief changelog published by Google, the zero-day is located in V8, the component of Chrome that handles JavaScript.
Chrome users are advised to update their browser to version 86.0.4240.183 or later.

Second zero-day vulnerability in two weeks
Google has discovered and patched two zero-day vulnerabilities in the last two weeks.
On October 20, Google also released a security update for Chrome to fix CVE-2020-15999, a zero-day vulnerability in Chrome's FreeType library.
As Google revealed last week, this Chrome zero-day was used alongside a Windows zero-day (CVE-2020-17087).
The Chrome bug was used to execute malicious code within Chrome, while the Windows bug was used to elevate the code's privileges and attack the underlying Windows.
Microsoft is expected to fix this bug on November 10th, with the next Patch Tuesday. Google did not clarify whether these two vulnerabilities were exploited by the same malicious actor.
