Google patches a Chrome zero-day bug found by its Threat Analysis Group, the third actively exploited Chrome zero-day discovered in the past year
Context & Ripple Effects
Google's Threat Analysis Group — the team built to track government-backed attackers — found this bug being used before anyone else did, making the discovery itself the story: the third actively exploited Chrome zero-day inside a year. It follows the sandbox-escaping zero-day Google disclosed in March 2019, which the company later confirmed was chained with a separate Windows 7 32-bit flaw Microsoft had to fix on its side.
The cadence only tightens from here: by November 2020 Google had patched five Chrome zero-days in three weeks, and later coverage shows the same pipeline surfacing a zero-day exploited by a commercial spyware vendor in 2023 and seven zero-day fixes in 2024 alone. This February 2020 patch is an early data point in that escalation.
First-order effects
- Chrome users and enterprise admins face another forced update cycle, with the exploit already in the wild rather than sitting in a researcher's report.
- The Threat Analysis Group's attribution role means the patch doubles as a signal about who is attacking — targeted users, not just opportunistic ones, are the affected population.
Second-order effects
- Attackers demonstrated in 2019 that a Chrome zero-day pairs well with an OS-level flaw, so each browser patch pushes exploit chains toward whatever unpatched system bug sits underneath.
- The accelerating count — five zero-days in three weeks by late 2020 — pressures Google to shorten its patch-to-deployment window and makes Chrome update latency a security metric enterprises watch.
Third-order effects
- If the pattern holds, browser zero-days stop being exceptional incidents and become a standing operational rhythm, with commercial spyware vendors as a durable source of demand for these exploits.
- Sustained in-the-wild exploitation of Chrome shifts the security burden toward automatic, silent updates and makes the browser vendor, not the user or IT team, the effective first responder.
The trend: Chrome zero-days are moving from rare disclosures to a routine emergency-patch cadence, driven by Google's own threat-intelligence tracking and a growing market for weaponized browser exploits.