Google releases patch for a Chrome zero-day vulnerability being used in the wild that allows hackers to escape sandbox protections via malicious websites
Attention readers, if you are using Chrome on your Windows, Mac, and Linux computers, you need to update your web browsing software immediately …
The Hacker NewsSwati Khandelwal
Context & Ripple Effects
This is the second sandbox-escape emergency Google has had to disclose in 2019 alone: back in [[a:939284|March it confirmed that what looked like a routine Chrome patch was actually covering a sandbox-escaping exploit already in active use]]. The difference now is that Google is flagging the vulnerability as a zero-day from the start, meaning attackers were exploiting it before any fix existed.
The disclosure also fits a pattern that has only accelerated since: Google went on to ship actively-exploited zero-day patches in October 2020 and April 2023, and by May 2024 was fixing its fifth in-the-wild Chrome zero-day of the year. Each event reinforces that Chrome's sandbox — the core defense separating web content from the operating system — is the specific layer attackers keep targeting.
First-order effects
Windows, Mac, and Linux users running Chrome are exposed right now: a malicious website alone can trigger the exploit and escape the sandbox, so the update is the only immediate mitigation until browsers auto-update.
Second-order effects
Enterprises managing large Chrome fleets face compressed patching timelines, because a website-delivered sandbox escape requires no user action beyond visiting a page — making delayed rollouts a direct attack surface.
Third-order effects
If the cadence holds — one or more exploited Chrome zero-days per year across 2019–2024 — browser vendors will be pushed to treat sandbox integrity as a continuously contested boundary rather than a static guarantee, with faster release pipelines and defense-in-depth inside the renderer as the response.
The trend: Chrome zero-days exploited in the wild have shifted from rare emergencies to a recurring annual patching rhythm, with sandbox escapes and the V8 engine as the recurring targets.
A few days ago our technologies caught a new Chrome 0day exploit used in the wild and we reported it to Google. Just released-Chrome 78 patches it, credits to my colleagues @antonivanovm and Alexey Kulaev for finding the bug. https://chromereleases.googleblog.com/ ...
Recently, we caught a new unknown #0day exploit for #Google's Chrome browser CVE-2019-13720. Since our discovery, Google has released a Chrome update for Windows, Mac and Linux users. More details on Operation WizardOpium attacks below. https://securelist.com/...
“Google is aware of reports that an exploit for CVE-2019-13720 exists in the wild” Manually update your Google Chrome to version 78.0.3904.87 in the menu Help > About Google Chrome https://chromereleases.googleblog.com/ ...
👀 UPDATE Kaspersky researchers, who reported #Chrome 0-day exploit to #Google, has now released more technical details about the #cyberattack, which it calls “Operation WizardOpium.” Read: https://thehackernews.com/... #infosec | #cybersecurity | #technews https://twitter.com/...
Attention - Update Your @GoogleChrome Browser Now! New Chrome 0-day Bug Under Active Attacks. The latest version 78.0.3904.87 has been released today by @Google. More details on @thehackersnews https://thehackernews.com/... https://twitter.com/...
Interesting that this Chrome bug was an all platform RCE+SBX. I wonder which companies are updating their catalogs s/0day/1day/ ... There is no mention of an LPE. I guess the functionality of the malware doesn't require it? https://securelist.com/...
Chrome 0-Day fixed announced, update your browser immediately. The stable channel has been updated to 78.0.3904.87 for Windows/Mac/Linux https://chromereleases.googleblog.com/ ... Ubuntu/Debian Linux user run “sudo apt update && sudo apt upgrade”. Fedora/RHEL/CentOS Linux users r…