Google has released Chrome 94.0.4606.71 for Windows, Mac, and Linux, aiming to fix two zero-day vulnerabilities that were being exploited by malicious actors.

See also: Windows 11: The Store is open to third-party app stores
“Google is aware that CVE-2021-37975 and CVE-2021-37976 are being exploited out,” the company revealed in the list of security fixes fixed in yesterday’s release of Google Chrome.
Google has started rolling out Chrome 94.0.4606.71 to users around the world, in the Stable Desktop , and it should be available to all users in the coming days.
Those who wish to install the update immediately can go to the Chrome menu > Help > About Google Chrome and the browser will begin performing the update.
Google Chrome will also check for available updates and install them the next time you start the web browser.
While this version of Chrome includes fixes for a total of four security vulnerabilities, the two zero-days are concerning, as they are known to have already been exploited by hackers.
See also: Apple Pay VISA: Allows hackers to make payments on locked iPhones

The first zero-day, codenamed CVE-2021-37976, is described as “Kernel Information Leak” and has a Medium severity level. This vulnerability was discovered by Clément Lecigne from Google TAG, with technical assistance from Sergei Glazunov and Mark Brand from Google Project Zero, on September 21, 2021.
The second zero-day, codenamed CVE-2021-37975, is a high-severity memory corruption bug in Chrome's V8 JavaScript engine. The researcher who disclosed the vulnerability on September 24th wished to remain anonymous.
Memory corruption errors are commonly used to execute remote code or to escape the browser's security sandbox.
See also: Google Chrome V8 JavaScript engine vulnerability: Update immediately
At this time, there are no further details on how these vulnerabilities were used in attacks, but they may be published in future reports from Google TAG or Project Zero.
