Security Magazine logo
search
cart
facebook twitter linkedin youtube
  • Sign In
  • Create Account
  • Sign Out
  • My Account
Security Magazine logo
  • NEWS
    • Security Newswire
    • Technologies & Solutions
  • MANAGEMENT
    • Leadership Management
    • Enterprise Services
    • Security Education & Training
    • Logical Security
    • Security & Business Resilience
    • Profiles in Excellence
  • PHYSICAL
    • Access Management
    • Fire & Life Safety
    • Identity Management
    • Physical Security
    • Video Surveillance
    • Case Studies (Physical)
  • CYBER
    • Cybersecurity News
    • More
  • BLOG
  • COLUMNS
    • Career Intelligence
    • Cyber Tactics
    • Cybersecurity Education & Training
    • Leadership & Management
    • Security Talk
  • EXCLUSIVES
    • Annual Guarding Report
    • Most Influential People in Security
    • The Security Benchmark Report
    • Top Guard and Security Officer Companies
    • Top Cybersecurity Leaders
    • Women in Security
  • SECTORS
    • Arenas / Stadiums / Leagues / Entertainment
    • Banking/Finance/Insurance
    • Construction, Real Estate, Property Management
    • Education: K-12
    • Education: University
    • Government: Federal, State and Local
    • Hospitality & Casinos
    • Hospitals & Medical Centers
    • Infrastructure:Electric,Gas & Water
    • Ports: Sea, Land, & Air
    • Retail/Restaurants/Convenience
    • Transportation/Logistics/Supply Chain/Distribution/ Warehousing
  • EVENTS
    • Industry Events
    • Webinars
    • Solutions by Sector
    • Security 500 Conference
  • MEDIA
    • Interactive Spotlight
    • Photo Galleries
    • Podcasts
    • Polls
    • Videos
      • Cybersecurity & Geopolitical Discussion
      • Ask Me Anything (AMA) Series
  • MORE
    • Call for Entries
    • Classifieds & Job Listings
    • Newsletter
    • Sponsor Insights
    • Store
    • White Papers
  • EMAG
    • eMagazine
    • This Month's Content
    • Advertise
  • SIGN UP!
CybersecurityManagementSecurity NewswireTechnologies & SolutionsCybersecurity News

Chrome gets patched again, but 83% of users aren’t running the latest version

By Maria Henriquez
google
November 20, 2020

According to Menlo Security, Google Chrome users don't always take time to relaunch browser updates, and some legacy applications don't support new versions of Chrome.

Menlo Labs discovered that there are 49 different versions of Chrome being used by their customers as of November 17. Nearly two-thirds (61 percent) are running the latest build (.86) while just over a quarter (28 percent) are running one version prior (.85). Out of the customers running .86, a staggering 83 percent are running versions of Chrome that are vulnerable (<Chrome/86.0.4240.198). If these customers were using legacy-based detection approaches, these active zero days would have been a risk for them, says Menlo Labs.

The chart below shows the top five versions of Chrome 86 seen on the Menlo platform as of November 17. The data shows that even though a patched version of the browser may be available for more than six days, customers are still not running these versions.

menlo

Tim Wade, Technical Director, CTO Team at Vectra, a San Jose, Calif.-based provider of technology which applies AI to detect and hunt for cyberattackers, explains that so long as there are zero days, which appears to be an indefinitely long, unceasing period of time, prevention will have a failure rate. 

"Further, the current state of organizational overinvestment in prevention is almost always an exercise in expensive, marginal (if any) increase in capability rather than a transformative increase in capability – at the stifling cost of paralyzed business objectives and increasingly constrained productivity. What’s more important than prevention is resilience, which involves identifying security investments that minimize the impact of an attack. And yes – so long as adversaries can enjoy enormous economies of scale through Chrome – it’s nearly everywhere – it will continue to receive targeted attacks," says Wade. 

Jack Mannino, CEO at nVisium, a Falls Church, Virginia-based application security provider, notes, that because web browsers interact with many different software packages on an operating system, it makes it impossible for a single product to protect web users from all conceivable attacks delivered through the browser. 

Mannino adds, "Attackers will continue targeting web browsers because this remains a great entry point to compromising endpoints inside of an organization. Browsers are a great way to deliver exploits across a variety of technologies supported by browser extensions and plugins. Web browsers tend to be patched faster in many organizations than other applications and packages. Extensions tend to be updated less frequently, with less enterprise controls enforced for hardening these additional attack surfaces." 

Hank Schless, Senior Manager, Security Solutions at Lookout, a San Francisco, Calif.-based provider of mobile security solutions, says, "Since the vulnerabilities are in the app itself, it requires more than just monitoring web traffic to prevent zero days. Mobile app vulnerabilities will always pose risk for organizations. In order to have an airtight security strategy, you need to know when vulnerable apps are present in your fleet as soon as they’re disclosed. Since it takes time for people to update their apps, attackers will continue to target the Chrome browser."

"These vulnerabilities are only patched if the user updates their app. Since many people don’t have automatic updates turned on, it’s likely attackers could still find success in exploiting these vulnerabilities. In the case of a successful exploit on mobile, the threat actor gains access to anything the Chrome app has access to. This includes browsing history, the camera and microphone, and location data. Malicious access to this data could put corporate data at risk if the user accesses any corporate resources through Chrome. Exfiltration of this type of data could also lead to compliance and other regulatory violations,"

Without visibility into the mobile apps on your employees’ mobile devices, it’s impossible to tell whether a vulnerable app could be threatening your corporate infrastructure, Schless adds. "Most everyone has a tool in place that does this for computer apps. With the amount of data access mobile devices have now, they should be treated with the same priority when it comes to your security strategy. Using a tool that can provide actionable information on mobile vulnerability and patch management is key to preventing a breach."

Zero Trust is also a big part of this, Schless explains. "You need to be able to extend policies to mobile devices that require them to have the most up-to-date version of apps in order to access corporate infrastructure.  Executing this type of policy is a best practice of ensuring strong mobile risk and compliance management. "

KEYWORDS: cyber security Google security vulnerability

Share This Story

Looking for a reprint of this article?
From high-res PDFs to custom plaques, order your copy today!

Maria Henriquez is a former Associate Editor of Security. She covered topics including cybersecurity and physical security, risk management and more.

Recommended Content

JOIN TODAY
To unlock your recommendations.

Already have an account? Sign In

  • Cyber tech background

    Security’s Top Cybersecurity Leaders 2026

    Security magazine’s Top Cybersecurity Leaders 2026 award...
    Top Cybersecurity Leaders
  • Iintegration and use of emerging tools

    Future Proof Your Security Career with AI Skills

    AI’s evolution demands security leaders master...
    Career Intelligence
    By: Jerry J. Brennan and Joanne R. Pollock
  • The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report surveys enterprise...
    The Security Benchmark Report
    By: Rachelle Blair-Frasier
Manage My Account
  • Security Newsletter
  • eMagazine Subscriptions
  • Manage My Preferences
  • Online Registration
  • Mobile App
  • Subscription Customer Service

More Videos

Sponsored Content

Sponsored Content is a special paid section where industry companies provide high quality, objective, non-commercial content around topics of interest to the Security audience. All Sponsored Content is supplied by the advertising company and any opinions expressed in this article are those of the author and not necessarily reflect the views of Security or its parent company, BNP Media. Interested in participating in our Sponsored Content section? Contact your local rep!

close
  • Northland Controls sponsored content
    Sponsored byNorthland Controls

    The Execution Gap: Why Great Security Design Doesn't Always Deliver Great Security

Popular Stories

Security's Most Influential people 2026

Security’s Most Influential People in Security 2026

Man in suit looking out window at city

Why GSOCs and Protective Intelligence Are the Cornerstone of Executive Protection

Person working on laptop

When Cyber Meets Physical: Rethinking Data Management for a New Threat Landscape

Black laptop keyboard with white lighting

Fighting Fire with Fire: How Businesses Are Using AI to Enhance Risk Management

Police lights

Family of Fatally Shot Security Guard Seeking Answers


AlertMedia sponsored webinar

Events

September 22, 2026

How to Detect, Verify, and Respond to AI-Driven Disinformation

LIVE: September 22, 2026 at 2 PM EDT Identify emerging threats, validate information with confidence, and coordinate an effective response across your organization. Learn how to build the people, processes, and technology needed to improve speed-to-truth.

September 24, 2026

Physical Security Under the Microscope: The Top 4 Gaps That Fail Compliance Audits

LIVE: September 24, 2026 at 2 PM EDT Security and compliance reviews of physical security devices tend to fail for the same reasons. Learn the gaps that trip up these reviews, and why they're getting harder to ignore as scrutiny on connected devices increase. 

View All Submit An Event

Products

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

See More Products

Related Articles

  • Man and women in office

    83% of organizations faced at least one account takeover the past year

    See More
  • retail-enews

    83% of top 30 US retailers have online vulnerabilities, posing cybersecurity threats

    See More
  • protect-cyber-security-freepik783.jpg

    83% of companies suffer business damage when down for 24 hours

    See More

Related Products

See More Products
  • The Database Hacker's Handboo

  • Risk Analysis and the Security Survey, 4th Edition

  • 9780367259044.jpg

    Understanding Homeland Security: Foundations of Security Policy

See More Products
×

Sign-up to receive top management & result-driven techniques in the industry.

Join over 20,000+ industry leaders who receive our premium content.

SIGN UP TODAY!
  • RESOURCES
    • Advertise
    • Contact Us
    • Store
    • Want More
  • SIGN UP TODAY
    • Create Account
    • eMagazine
    • Newsletter
    • Customer Service
    • Manage Preferences
  • SERVICES
    • Marketing Services
    • Reprints
    • Market Research
    • List Rental
    • Survey/Respondent Access
  • STAY CONNECTED
    • LinkedIn
    • Facebook
    • YouTube
    • X (Twitter)
  • PRIVACY
    • PRIVACY POLICY
    • TERMS & CONDITIONS
    • DO NOT SELL MY PERSONAL INFORMATION
    • PRIVACY REQUEST
    • ACCESSIBILITY

Copyright ©2026. All Rights Reserved BNP Media, Inc. and BNP Media II, LLC.

Design, CMS, Hosting & Web Development :: ePublishing