Google patches two Chrome zero-days that were exploited in the wild, after tips from anonymous sources; Google has patched five Chrome zero-days in three weeks
what to do now Elizabeth Montalbano / Threatpost : 2 More Google Chrome Zero-Days Under Active Exploitation Ravie Lakshmanan / The Hacker News : Two New Chrome 0-Days Under Active Attacks - Update Your Browser Eduard Kovacs / SecurityWeek : Google Patches Two More Chrome Zero-Days Exploited in Attacks Sabina Weston / IT PRO : Microsoft patches actively exploited Windows Kernel flaw Computing : Patch Tuesday: Microsoft addresses Windows zero-day vulnerability and 111 others Pierluigi Paganini / Security Affairs : Google addresses two new Chrome zero-day flaws Brianna Provenzano / Gizmodo : You Need to Update Chrome Right Now Tweets: Catalin Cimpanu / @campuscodi : BREAKING: Google patches two more Chrome zero-days This includes: -CVE-2020-16013 - impacts Chrome V8 JS engine -CVE-2020-16017 - impacts Chrome's Site Isolation feature Google has now patched five Chrome zero-days in three weeks https://www.zdnet.com/... https://twitter.com/... Catalin Cimpanu / @campuscodi : Of note here is that while Google discovered the first three zero-days on its own, these two were discovered and reported by an anonymous source. There's certainly something going on that Google isn't telling us. That's for sure. Also, breaking Site Isolation is quite the feat.
Context & Ripple Effects
This is the second consecutive month Google has shipped emergency Chrome fixes for flaws attackers are already using — it patched another actively exploited zero-day just weeks earlier in an October security update. Unlike the February zero-day found by Google's own Threat Analysis Group, these two arrived via tips from anonymous sources, meaning outside researchers or affected parties surfaced them.
The three-week tally of five zero-days puts Chrome on a pace consistent with the multi-zero-day years captured in later coverage, and it lands in the same week Microsoft patched its own actively exploited Windows Kernel flaw — echoing the browser-plus-OS exploit chains Google disclosed back in its 2019 write-up of a Chrome zero-day paired with a Windows 7 bug.
First-order effects
- Every Chrome user on an unpatched build is exposed to two known-exploited vulnerabilities until they update; Google's urgent release cycle exists precisely to shrink that window.
Second-order effects
- The simultaneous Microsoft Windows Kernel zero-day fix revives the chained-exploit concern from 2019, where attackers combined a Chrome flaw with a Windows bug — pushing both vendors toward faster cross-platform disclosure and coordinated patching.
Third-order effects
- If anonymous-tip-driven, in-the-wild discoveries keep arriving at this cadence, out-of-band browser patching becomes routine infrastructure maintenance rather than an exception — and the browser hardens into the primary battleground where defenders' update velocity, not perimeter tools, decides outcomes.
The trend: Chrome's steady stream of actively exploited zero-days is normalizing continuous emergency patching and shifting browser security toward a speed contest between vendor response and attacker exploitation.