Google Chrome continues to dominate the web browser market with more than two billion users worldwide. But the thing is, it's also a hotbed of hackers, forcing Google to issue its third urgent update warning in a month. The new zero-day exploit is said to be a V8 JavaScript engine. What exactly does that mean? You'll find out below!

In an official blog post, Google revealed that a new “zero-day” exploit (CVE-2021-30563) has been discovered in Chrome and – like the previous attack – follows an anonymous update. Unlike most security vulnerabilities, a zero-day classification means that the exploit has been made public before the company could patch it. Writing on its blog, Google confirmed that it is “aware of an exploit being released for CVE-2021-30563.”.
See also: Google Chrome: Eighth zero-day bug fixed in six months
Little is known about the exploit other than Google's categorization that it is a "Type Confusion in V8" - which is the open-source JavaScript engine at the heart of Chrome. This secrecy is typical of zero-day bugs, as Google tries to minimize the spread of the attack before Chrome users have a chance to upgrade and protect themselves.
To address this new threat, all Chrome users should go to Settings > Help > About Google Chrome. If your browser version on Linux, macOS , and Windows is listed as 91.0.4472.164 or above, you’re already safe. If not, manually check for updates and restart your browser once the update is complete. Google also confirmed that six other “high”-level threats have been fixed in this version of Chrome, as well as a single “medium”-level vulnerability.
CVE-2021-30563 is the eighth zero-day vulnerability found in Chrome this year and the third in a month. It's great that Google typically releases security patches for zero-day attacks within a few days, but ultimately their effectiveness is determined by how quickly Chrome users update browsers .
See also: Google Chrome: Gets HTTPS-Only Mode for Secure Browsing
Attacks on Chrome have been particularly prevalent in recent months, most notably by a group called PuzzleMaker. The group has succeeded in chaining Chrome zero-day bugs to install malware on Windows. Microsoft itself issued an urgent security advisory for Windows users about this in June.
Chrome users would be wise to keep an eye on updates and ensure that both your browser and operating system are up to date.

But how dangerous is a zero-day?
On the first day, any bug or vulnerability in an online or offline software has not yet been patched by the company or its developer. Thus, zero-day exploits guarantee a high probability of successful attack for attackers. This is why zero-day exploits are very dangerous for the targeted individual or organization.
It is believed that advanced cybercrime or hacking groups – especially some organized cybercrime – maintain a collection of zero-day vulnerabilities to attack high-value targets. Their list typically includes foreign government websites, financial or popular institutions, or other important targets.
For example, Mozilla Firefox had two unknown zero-day bugs in June 2019 – “Type confusion in Array.pop” and “Sandbox escape using Prompt: Open”. Unfortunately, a hacking group discovered these zero-day vulnerabilities and used them to attack various cryptocurrency exchanges.
See also: How to use Do Not Disturb on Chromebook
The problem with zero-day vulnerabilities is not resolved until users install the required update or patch on their systems. Of course, this process takes a long time, and then there are users who are unable to fix a zero-day vulnerability.
What is the end result? Attackers try to find unpatched systems and target the n-day vulnerability to gain access to vulnerable systems – especially the most critical targets like large corporations.
Information source: forbes.com
