Chrome 143.0.7499.109/101 for Windows and macOS, and 143.0.7499.109 for Linux available
This emergency Chrome update patches a zero-day vulnerability.
The new Chrome versions 143.0.7499.109/101 for Windows and macOS, and 143.0.7499.109 for Linux fix three vulnerabilities. According to Google, one of these vulnerabilities is already being exploited in attacks. Developers of other Chromium-based browsers will follow suit in the coming days; Vivaldi has already released an update.
The Chrome Release Blog lists the fixed security vulnerabilities, which were apparently all reported to Google by external researchers.
Google classifies one of these vulnerabilities as high risk. However, no details about the flaw are yet available. The description simply states: [466192044] High: Under coordination. So far, there is neither a CVE number nor information about the type of vulnerability or the affected component. All that is clear for now is that it is a zero-day vulnerability. Further information should follow soon. The two other vulnerabilities are listed as medium risk.
On December 2nd, Google released Chrome version 143, a major release that addresses several vulnerabilities. Chrome typically updates automatically when a new version is available. You can manually check for updates via the menu item Help > About Google Chrome. Google also released Chrome for Android (version 143.0.7499.1092) and Chrome for iOS (version 143.0.7499.108). The Android version fixes the same vulnerabilities as the desktop versions. The Extended Stable Channel for Windows and macOS now includes Chromium version 142.0.7499.235.