Skip to content
FIX Google Chrome Zero Day Vulnerability

FIX Google Chrome Zero Day Vulnerability

Written By Jitesh Kumar
Last Updated December 21, 2023
Posted In Windows
SHARE

Google has released security updates to address chrome zero day vulnerability CVE-2023-7024. The heap buffer overflow vulnerability exploits the high-severity vulnerability, which could allow an attacker to execute arbitrary code on the affected system.

The Stable channel has been updated to 120.0.6099.129 for Mac, and Linux and 120.0.6099.129/130 for Windows, which will roll out over the coming days/weeks. It is recommended to upgrade to the Chrome version 120.0.6099.129/130 for Windows, macOS, and Linux to mitigate potential threats.

Google is aware that an exploit for CVE-2023-7024 exists in the wild. Access to bug details and links may be restricted until most users are updated with a fix. We will also retain restrictions if the bug exists in a third party library that other projects similarly depend on but haven’t yet fixed.

The Extended Stable channel has been updated to 120.0.6099.129 for Mac and 120.0.6099.130 for Windows, which will roll out over the coming days/weeks.

Patch My PC

Google Chrome Zero Day Vulnerability

The high-severity zero-day vulnerability CVE-2023-7024 is due to a heap based buffer overflow bug in the WebRTC open-source framework of many other web browsers, chromium based browsers and browsers such as Mozilla Firefox, Safari, to provide Real-Time Communications (RTC) capabilities via JavaScript APIs.

High CVE-2023-7024: Heap buffer overflow in WebRTC. Reported by Clément Lecigne and Vlad Stolyarov of Google’s Threat Analysis Group on 2023-12-19

FIX Google Chrome Zero Day Vulnerability Fig.1
FIX Google Chrome Zero Day Vulnerability Fig.1

Update Google Chrome Browser with the latest Patch

The Google Chrome Stable channel has been updated to 120.0.6099.129 for Mac, and Linux and 120.0.6099.129/130 for Windows, which will roll out over the coming days/weeks.

If you haven’t blocked automatic updates for Google Chrome or managed from the organization. Google Chrome can automatically update when a new version of the browser is available on your device.

Normally updates happen in the background when you close and reopen your computer’s browser. But if you haven’t closed your browser in a while, you might see a pending update, To update Google Chrome:

  • On your device, open Chrome. At the top right, click More More.
  • Click Help and then About Google Chrome.
  • Click Update Google Chrome. You’re on the latest version if you can’t find this button.
FIX Google Chrome Zero Day Vulnerability Fig.2
FIX Google Chrome Zero Day Vulnerability Fig.2

SCCM and Intune application model is the feature-rich option to update Chrome for a large organization. If you are using SCCM, or Intune for managing the devices in your enterprise, then you should use the application model to update Google Chrome, Patch Chrome With SCCM 3rd Party Software Update Feature.

FIX Google Chrome Zero Day Vulnerability

A history of fixed Chromium security bugs is best found via security notes in Stable Channel updates on the Google Chrome releases blog. You can also find fixed, publicly visible Type=Bug-Security bugs in the issue tracker (note: security bugs automatically become publicly visible 14 weeks after they are fixed).

We are on WhatsApp. To get the latest step-by-step guides and news updates, Join our Channel. Click here –HTMD WhatsApp.

Author

About Author – JiteshMicrosoft MVP, has over six years of working experience in the IT Industry. He writes and shares his experiences related to Microsoft device management technologies and IT Infrastructure management. His primary focus is Windows 10/11 Deployment solution with Configuration Manager, Microsoft Deployment Toolkit (MDT), and Microsoft Intune

Written by

Jitesh has over 5 years of working experience in the IT Industry. He writes and shares his experiences related to Microsoft device management technologies and IT Infrastructure management. His primary focus area is Windows 10 Deployment solution with Configuration Manager, Microsoft Deployment Toolkit (MDT), and Microsoft Intune.

Discussion

Join the discussion

Your email address will not be published. Required fields are marked *

Related guides

Intune

Windows 11 KB5101650 KB5099414 July 2026 Patch and 3 Zero Day Vulnerabilities and 570 Flaws

Key Takeaways Windows 11 KB5101650 KB5099414 July 2026 Patch and 3 Zero Day Vulnerabilities and 570 Flaws! In the July 2026 Patch, Microsoft introduced new features designed to improve the overall Windows experience. The update adds enhancements to Windows Update for more flexible update management and introduces Point-in-Time Restore, providing an additional recovery option for […]

AC Anoop C Nair 9 min read
Intune

BitLocker Prompt Issue After June Patch KB5094126 Secure Boot UEFI 2023 Certificate Update

Key Takeaways BitLocker Prompt Issue After June Patch KB5094126 Secure Boot UEFI 2023 Certificate Update! After deploying the June 2026 Windows update (KB5094126), some HP EliteDesk 800 G6 devices began prompting for the BitLocker recovery key after every reboot. Based on our investigation, the Secure Boot UEFI 2023 certificate update does not appear to be […]

AC Anoop C Nair 5 min read
Microsoft Defender for Endpoint

Microsoft Defender for Endpoint EDR Updates are now Separate from Monthly Windows Security Updates for Faster Protection

Key Takeaways In this post, we are discussing how Microsoft Defender for Endpoint EDR Updates Will Be Delivered Through Microsoft Update. Microsoft has introduced a new update model for Microsoft Defender for Endpoint Detection and Response (EDR) security updates. Previously, these updates were included with the monthly Windows security updates. This change enables Microsoft to […]

AC Anoop C Nair 5 min read