Google first to patch Flash bug with Chrome update

Takes advantage of deal with Adobe to push zero-day fix a week before others get protection

Google on Tuesday updated Chrome, patching a flaw in the browser's copy of Flash Player.

The move let Chrome beat rival browsers to the punch: Users of Internet Explorer (IE), Firefox, Safari and Opera won't receive a Flash update from Adobe until next week.

On Monday, Adobe announced that attackers are exploiting an unpatched, or "zero-day," vulnerability in Flash Player using malicious Microsoft Excel documents attached to e-mail messages. Adobe said it would patch Flash Player for Windows, Mac OS X and Linux sometime next week, but did not put a date on the calendar.

Yesterday, Google pushed a Chrome update to users running the stable and beta builds of the browser.

"This release contains an updated version of the Adobe Flash player," Jason Kersey, a Chrome program manager, said in a Tuesday post to a Google blog.

After updating Chrome to version 10.0.648.134, the browser reports that it's running Flash Player, a step up from the bundled with the last update of the browser.

Adobe confirmed today that Chrome's integrated copy of Flash includes the patch for the zero-day vulnerability.

"As part of our collaboration with Google, Google receives updated builds of Flash Player for integration and testing," said Adobe spokeswoman Wiebke Lipps today. "Once testing is completed for Google Chrome, the release is pushed via the Chrome auto-update mechanism."

Adobe is still testing the patched Flash Player across its full list of supported platforms, which range from Windows and Mac OS X to Linux and Android, Lipps said.

Google has been including fixes for Flash Player in its Chrome updates since April 2010. Chrome is the only browser to automatically update Flash Player with its own patch mechanism.

Chrome users have gotten the jump on others before when it comes to Flash fixes. Last September, for example, Google updated the browser, and delivered a patched Flash Player, three days before Adobe.

Chrome 10.0.648.134 with the patched Flash Player can be downloaded can be downloaded for Windows, Mac OS X and Linux from Google's Web site. Users already running the browser will be updated automatically.

Gregg Keizer covers Microsoft, security issues, Apple, Web browsers and general technology breaking news for Computerworld. Follow Gregg on Twitter at @gkeizer or subscribe to Gregg's RSS feed. His e-mail address is

Read more about browsers in Computerworld's Browsers Topic Center.

Join the CSO newsletter!

Error: Please check your email address.

Tags applicationsGoogleMicrosoftsecuritybrowserssoftwareinternet

More about Adobe SystemsAppleExcelGoogleLinuxMicrosoftTopic

Show Comments

Featured Whitepapers

Editor's Recommendations

Solution Centres

Stories by Gregg Keizer

Latest Videos

  • 150x50

    CSO Webinar: Will your data protection strategy be enough when disaster strikes?

    Speakers: - Paul O’Connor, Engagement leader - Performance Audit Group, Victorian Auditor-General’s Office (VAGO) - Nigel Phair, Managing Director, Centre for Internet Safety - Joshua Stenhouse, Technical Evangelist, Zerto - Anthony Caruana, CSO MC & Moderator

    Play Video

  • 150x50

    CSO Webinar: The Human Factor - Your people are your biggest security weakness

    ​Speakers: David Lacey, Researcher and former CISO Royal Mail David Turner - Global Risk Management Expert Mark Guntrip - Group Manager, Email Protection, Proofpoint

    Play Video

  • 150x50

    CSO Webinar: Current ransomware defences are failing – but machine learning can drive a more proactive solution

    Speakers • Ty Miller, Director, Threat Intelligence • Mark Gregory, Leader, Network Engineering Research Group, RMIT • Jeff Lanza, Retired FBI Agent (USA) • Andy Solterbeck, VP Asia Pacific, Cylance • David Braue, CSO MC/Moderator What to expect: ​Hear from industry experts on the local and global ransomware threat landscape. Explore a new approach to dealing with ransomware using machine-learning techniques and by thinking about the problem in a fundamentally different way. Apply techniques for gathering insight into ransomware behaviour and find out what elements must go into a truly effective ransomware defence. Get a first-hand look at how ransomware actually works in practice, and how machine-learning techniques can pick up on its activities long before your employees do.

    Play Video

  • 150x50

    CSO Webinar: Get real about metadata to avoid a false sense of security

    Speakers: • Anthony Caruana – CSO MC and moderator • Ian Farquhar, Worldwide Virtual Security Team Lead, Gigamon • John Lindsay, Former CTO, iiNet • Skeeve Stevens, Futurist, Future Sumo • David Vaile - Vice chair of APF, Co-Convenor of the Cyberspace Law And Policy Community, UNSW Law Faculty This webinar covers: - A 101 on metadata - what it is and how to use it - Insight into a typical attack, what happens and what we would find when looking into the metadata - How to collect metadata, use this to detect attacks and get greater insight into how you can use this to protect your organisation - Learn how much raw data and metadata to retain and how long for - Get a reality check on how you're using your metadata and if this is enough to secure your organisation

    Play Video

  • 150x50

    CSO Webinar: How banking trojans work and how you can stop them

    CSO Webinar: How banking trojans work and how you can stop them Featuring: • John Baird, Director of Global Technology Production, Deutsche Bank • Samantha Macleod, GM Cyber Security, ME Bank • Sherrod DeGrippo, Director of Emerging Threats, Proofpoint (USA)

    Play Video

More videos

Blog Posts

Market Place