HomeUpdatesGoogle: Fixes new zero-day vulnerability in Chrome browser

Google: Fixes new zero-day vulnerability in Chrome browser

Google has patched a new zero-day vulnerability in its Chrome browser (the fifth this year). The vulnerability is already being used in attacks.

Google Chrome zero-day vulnerability

Tracked as CVE-2024-4671 , it is a serious “user after free” vulnerability in the Visuals component, which handles rendering and displaying content in the browser . It was discovered and reported to Google by an anonymous researcher, and the company revealed that it is actively being used in attacks.

Exploiting Use after-free vulnerabilities can allow data leakage, code execution, or cause a crash.

See also: ArcaneDoor: Hackers use Cisco zero-day to compromise networks

Google has addressed the zero-day vulnerability with build 124.0.6367.201/.202 for Mac/Windows and 124.0.6367.201 for Linux. Users will receive the updates in the coming days/weeks. For users on the “Extended Stable” channel, the fixes will be available in build 124.0.6367.201 for Mac and Windows.

The Google Chrome browser automatically updates itself when a security update is released. However, if you are unsure, you can check the version by going to Settings > About Chrome. Click the “Relaunch” button to apply the update.

Google Chrome: Fifth zero-day vulnerability fixed this year

This is the fifth Chrome zero-day vulnerability to be patched this year. Three others were discovered during the Pwn2Own in Vancouver in March 2024.

See also: CrushFTP: Calls for immediate zero-day fix

In detail, the vulnerabilities that have been fixed:

CVE-2024-0519: A high severity out-of-bounds memory access vulnerability was identified in the Chrome V8 JavaScript engine, allowing remote attackers to exploit heap corruption via a specially crafted HTML page. The result is unauthorized access to sensitive information.

CVE-2024-2887: A high severity type confusion vulnerability in the WebAssembly (Wasm) standard. It allows remote code execution (RCE) by exploiting a crafted HTML page.

CVE-2024-2886: A use-after-free vulnerability in the WebCodecs API used by web applications to encode and decode audio and video. Attackers exploited this to allow remote code execution.

CVE-2024-3159: A high severity vulnerability in the Chrome V8 JavaScript engine. Remote attackers exploited this flaw using specially crafted HTML pages to gain access to data.

See also: Palo Alto Networks fixes zero-day firewall backdoor

Google: Fixes new zero-day vulnerability in Chrome browser

The above Chrome zero-day vulnerabilities are particularly worrisome. Fixing them prevents them from being exploited by malicious users.

Additionally, Chrome's security update increases confidence user in the browser. Users can be confident that Google takes their security seriously and is doing everything it can to ensure it.

Finally, these fixes ensure that Chrome remains compatible with the latest technological developments and security. This is particularly important for maintaining the efficiency and reliability of the browser.

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS