Google Releases New ‘Critical’ Security Fix For Desktop Chrome Users (2024)

If you are a Windows user with Chrome installed on your PC, then this latest warning will impact you—it’s critical you update your browser as soon as you can…

Updated 04/29; originally published 04/26.

Another Chrome security update has just been issued, with the Stable channel updated to 124.0.6367.78/.79. This release includes a critical fix to the underlying graphics engine of the type that has allowed attackers to execute code on target machines in the past—albeit no news yet as to any exploitation this time around.

The update also includes two high-severity memory fixes—the kind typically seen in such updates. Google has acknowledged that such memory vulnerabilities in its core engine are the most frequently discovered and exploited. As usual, there is no further information “until a majority of users are updated with a fix.”

Given that Google has designated the first fix—essentially a vulnerability to potential code manipulation—as critical, it seems highly likely it’s a credible threat. And once the fix becomes public, it’s important that users update as soon as they can—the clock is ticking for any exploitation.

ForbesWhatsApp Threatens To Remove 500 Million Users From AppBy Zak Doffman

MORE FOR YOU

Your Best Look Yet At The New iPhone 16
One Of The Best Robin Williams Comedies Ever Made Lands On Netflix Today
Drake And Kendrick Lamar Feud Timeline Lamar Drops Second Diss Track 6 16 In LA

Usually, a critical fix might have been the biggest Chrome news of the week, but not this time. The other news is that the death of Chrome’s dreaded tracking cookies has been delayed once again—this time into early 2025, at least.

The issue is Google’s need to balance the privacy of its users with the seemingly fair treatment of its advertisers, especially when it essentially plays both gamekeeper (as owner of the browser) and poacher (as the world’s largest ad machine).

“We recognize that there are ongoing challenges related to reconciling divergent feedback from the industry, regulators and developers,” Google said in a post mid-week, “and will continue to engage closely with the entire ecosystem.”

That’s a critical update of an entirely different kind.

The update comes as Google’s ongoing engagement with the UK’s Competition and Markets Authority (CMA) tries to carve a path through this messy situation. “We will not complete third-party cookie deprecation during the second half of Q4,” Google confirmed. “Assuming we can reach an agreement, we envision proceeding with third-party cookie deprecation starting early next year.”

Google is in something of a bind here, given its unique role in the industry. As web users become ever more privacy savvy, the gap between where Chrome is today and Apple’s Safari remains too wide. Chrome is an excellent browser, and its users rightly want to see it line up more closely with the alternatives.

Google seems to agree—notwithstanding its awkward Incognito Mode stumble—but it needs to find a compromise that doesn’t kill its ad model as well as those cookies.

Meanwhile, the bigger open question is around AI, of course, and just what this will mean for browser searching and advertising in the coming years. All told, by the time these cookies finally disappear, we may be in new territory anyway.

ForbesWhy You Should Change How You Make Calls On Your iPhoneBy Zak Doffman

04/29 update: To be fair to Google, Chrome’s regular security updates—whether addressing vulnerabilities discovered by external researchers or by Google itself, front-end an ongoing program to improve the security of the world’s most popular browser.

As a recent example, the forthcoming Device Bound Session Credentials (DBSC) update should materially resolve the plague of session cookie theft, “by binding authentication sessions to the device... to disrupt the cookie theft industry since exfiltrating these cookies will no longer have any value.”

But these security advances are not always smooth running—and another such update, Chrome’s foray into post-quantum cryptography (PQC), seems to have hit a teething issue.

Put at its simplest, PQC aims to protect today’s data from tomorrow’s more advanced threats—the theory being that while today’s defenses are largely good enough, new quantum computing advances will likely break the best cryptography available today.

And while Google points out that “it’s believed that quantum computers that can break modern classical cryptography won’t arrive for 5, 10, possibly even 50 years from now,” the issue is the threat from “Harvest Now, Decrypt Later, in which data is collected and stored today and later decrypted once cryptanalysis improves.”

Google says that “the sooner we can update TLS to use quantum-resistant session keys, the sooner we can protect user network traffic against future quantum cryptanalysis,” and that “we are updating technical standards, testing and deploying new quantum-resistant algorithms, and working with the broader ecosystem to help ensure this effort is a success.”

But as Bleeping Computer reported over the weekend, “some ​Google Chrome users report having issues connecting to websites, servers, and firewalls after Chrome 124 was released last week with the new quantum-resistant X25519Kyber768 encapsulation mechanism enabled by default... The issue also affects security appliances, firewalls, networking middleware, and various network devices from multiple vendors (e.g., Fortinet, SonicWall, Palo Alto Networks, AWS).”

For now, “affected Google Chrome users can mitigate the issue by going to chrome://flags/#enable-tls13-kyber and disabling the TLS 1.3 hybridized Kyber support in Chrome,” but the option to disable PQC defenses will be removed once the technology is considered stable.

PQC hit the headlines earlier this year, with Apple’s announcement that it was updating iMessage to protect against the same threat. And while Apple presented this as a competitive advantage for iMessage over alternatives, the reality is that such technology is likely to become much more standard over the next few years.

But such tech is still fairly deep inside the rabbit hole, and you can expect many more unexpected issues as wider rollouts begin.

Google Releases New ‘Critical’ Security Fix For Desktop Chrome Users (2024)

FAQs

What is the warning about Google Chrome? ›

CERT-In issued a 'high' severity warning for Google Chrome desktop version due to vulnerabilities allowing remote attackers to obtain sensitive information. Multiple high-severity security flaws found in select versions, including Type Confusion in V8, Use after free in Dawn, and Use after free in V8.

What is Chrome security issue 2024? ›

Exploited in the wild, the high-severity Chrome vulnerability CVE-2024-5274 is described as a type confusion flaw in the V8 JavaScript and WebAssembly engine. To mitigate potential threats, users should upgrade to Chrome version 125.0. 6422.112/. 113 for Windows and macOS and version 125.0.

What is the new Chrome vulnerability? ›

Google on Monday shipped emergency fixes to address a new zero-day flaw in the Chrome web browser that has come under active exploitation in the wild. The high-severity vulnerability, tracked as CVE-2024-4761, is an out-of-bounds write bug impacting the V8 JavaScript and WebAssembly engine.

How do I get rid of Chrome security error? ›

You'll get this error if you have antivirus software that provides "HTTPS protection" or "HTTPS scanning." The antivirus is preventing Chrome from providing security. To fix the problem, turn off your antivirus software. If the page works after turning off the software, turn off this software when you use secure sites.

Why is Google giving me a security warning? ›

If there's ever any suspicious activity associated with your account, Google will let you know so you can secure your data. You may receive a “Suspicious sign-in prevented” email to let you know Google blocked someone from accessing your account.

Is the Chrome virus warning real? ›

Easy. If you don't have antivirus software on your computer, any virus alert you come across is fake. When you do have antivirus software, only trust alerts that appear in a window from your software. Pop-ups on web pages or in your browser are always fake.

Is Chrome being phased out? ›

In Short. Google is ending its support for older versions of Chrome in January 2022. The announcement matches Microsoft's Windows lifecycle policy.

Is Google Chrome safe from hackers? ›

Chrome is secure by default, protecting you from dangerous and deceptive sites that might steal your passwords or infect your computer.

Do I need to update Google Chrome? ›

To make sure you're protected by the latest security updates, Google Chrome can automatically update when a new version of the browser is available on your device. With these updates, you might sometimes notice that your browser looks different.

What is the most vulnerable browser in the world? ›

Google Chrome is the only browser with new vulnerabilities in the five days in October. Recent ones include CVE-2022-3318, CVE-2022-3314, CVE-2022-3311, CVE-2022-3309, and CVE-2022-3307. The CVE programme tracks security flaws and vulnerabilities across multiple platforms.

Is Chrome at risk? ›

Google has released an emergency security update for its Chrome browser, including a patch for a zero-day vulnerability that has exploit code released in the wild that could lead to data theft, lateral movement, malware implantation, and more.

How do I know if I have malware on Chrome? ›

You might have unwanted software or malware installed on your computer if you experience:
  1. Pop-up ads and new tabs that won't go away.
  2. Your Chrome homepage or search engine keeps changing without your permission.
  3. Unwanted Chrome extensions or toolbars keep coming back.

Why is Chrome suddenly saying everything is not secure? ›

When a website with a secure connection is accessed, the URL starts with “HTTPS” regardless of your browser. This indicates an encrypted connection. For the HTTPS to appear, it's necessary to use an SSL Certificate. So, if the website doesn't have this certificate, the “HTTPS Not Secure” Message in Chrome will appear.

How do I reset Chrome security? ›

On your computer, open Chrome. At the top right, click More > Settings > Advanced. On Chromebook, Linux, and Mac: Click Reset settings > Restore settings to their original defaults and then Reset settings. On Windows: Click Reset and cleanup > Reset settings to their original defaults > Reset settings.

Is Chrome having issues today? ›

Is Google Chrome Browser down today? According to its status page Google Chrome Browser is currently up.

What is the government warning on Chrome? ›

According to the report, the multiple vulnerabilities that have been found in Chrome could be exploited by hackers. This can lead to gaining access to “execute arbitrary code or cause a Denial of Service (DoS) condition, obtain sensitive information and bypass security restrictions on the targeted system.”

Is Google Chrome safe to use now? ›

Secure by default

Advanced technologies, such as site isolation, sandboxing, and predictive phishing protections, keep you and your data safe.

Why is Google Chrome giving me privacy warning? ›

A “your connection is not private” error means your browser cannot verify whether a website is safe to visit. Your browser issues this warning message to prevent you from visiting the site, because visiting an unsafe or unsecure site may put your personal information at risk.

How do I get rid of the Chrome warning? ›

On your computer, open Chrome. Settings. Security. Under "Safe Browsing," choose No protection (not recommended).

Top Articles
Latest Posts
Article information

Author: Errol Quitzon

Last Updated:

Views: 6593

Rating: 4.9 / 5 (59 voted)

Reviews: 90% of readers found this page helpful

Author information

Name: Errol Quitzon

Birthday: 1993-04-02

Address: 70604 Haley Lane, Port Weldonside, TN 99233-0942

Phone: +9665282866296

Job: Product Retail Agent

Hobby: Computer programming, Horseback riding, Hooping, Dance, Ice skating, Backpacking, Rafting

Introduction: My name is Errol Quitzon, I am a fair, cute, fancy, clean, attractive, sparkling, kind person who loves writing and wants to share my knowledge and understanding with you.