If you’re like the majority of internet users out there, then Google Chrome is your default web browser of choice. If that is the case however, you might want to install the latest Google patch ASAP. Security researchers at Kaspersky have found a new vulnerability that can hijack a user’s browser to inject malware that could lead to their entire system being put at risk.
Zero-day vulnerabilities are previously unknown software bugs that can be exploited by attackers to inflict serious and unexpected damage.
The detected exploit was used in what Kaspersky experts call “Operation WizardOpium”. Certain similarities in the code point to a possible link between this campaign and Lazarus attacks. Additionally, the profile of the targeted website is similar to what has been found in previous DarkHotel attacks, which have recently deployed comparable false flag attacks.
“The finding of a new Google Chrome zero-day in the wild once again demonstrates that it is only collaboration between the security community and software developers, as well as constant investment in exploit prevention technologies, that can keep us safe from sudden and hidden strikes by threat actors,”
Anton Ivanov, a security expert at Kaspersky.
The attack used a waterhole-style exploit to inject malicious JavaScript code into the Chrome main page, which then uses a profiling script to analyse the victim’s system and user credentials to see if version 65 or later of Chrome is installed or not.
Of course, Kaspersky has informed Google of its findings, and a patch has been released. If you’re a Chrome user, we urge you to install the patch as soon as possible and also keep whatever security software you’re using up to date.




