Η Google released today version 86.0.4240.198 of Chrome to fix two 0day that are already circulating on the internet.
These two errors mark the fourth and fifth 0days that Google has fixed in Chrome over the past three weeks.
The difference this time is that the first three 0days were discovered internally by Google security researchers, these two new ones were detected by anonymous sources.
Details of where and how the new Chrome 0days have been used have not yet been published.
In accordance with changelog Chrome 86.0.4240.198, the two new vulnerabilities are:
CVE-2020-16013 - Described as "inappropriate V8 application", where V8 is the Chrome component that manages JavaScript code.
CVE-2020-16017 - Described as a "use after free" memory corruption error in Site Isolation, the Chrome component that isolates the data of each site from each other.
It is not known at this time whether the two vulnerabilities have been used together, or individually. The first security breach was reported on Monday, while the second was reported on Wednesday.
So as you understand you should update your browser immediately.