HomeSecurityChrome: Code update for Type Confusion vulnerabilities

Chrome: Code update for Type Confusion vulnerabilities

Google has released a critical security update for its Chrome browser, which addresses several vulnerabilities, including two high-severity Type Confusion vulnerabilities in the V8 JavaScript engine .

See also: Google Chrome: New API for fast translation of complex content

Chrome Type Confusion

The update, which brings Chrome to version 129.0.6668.100/.101 for Windows and Mac and 129.0.6668.100 for Linux, includes three security fixes contributed by external researchers.

The most serious vulnerabilities in Chrome, CVE-2024-9602 and CVE-2024-9603, are Type Confusion flaws in V8, which if exploited, could allow arbitrary code execution.

This vulnerability can manifest in applications that interpret the same variable or memory location differently, including languages ​​such as PHP and Perl. Type Confusion can be exploited by attackers to corrupt memory and execute arbitrary code.

These vulnerabilities were reported by Seunghyun Lee (@0x10n) and @WeShotTheMoon and @Nguyen Hoang Thach of Starlabs, respectively, and have been rated as high severity due to their potential impact on system confidentiality and integrity.

See also: Infostealer bypasses Chrome's new cookie theft defenses

Google has hidden the full technical details of these Type Confusion vulnerabilities until the majority of users have updated to the latest version of Chrome, to prevent their exploitation.

google chrome vulnerabilities

However, the company has stressed the importance of updating to the latest version as soon as possible to ensure protection against these threats. The update also includes various fixes from internal audits, fuzzing, and other initiatives, which were detected using tools such as AddressSanitizer, MemorySanitizer, UndefinedBehaviorSanitizer, Control Flow Integrity, libFuzzer, or AFL.

To update Chrome, users can navigate to the Help|About menu, which will automatically start downloading the latest version, if available. It is important to restart the browser after installing the update to ensure that the new security patches are applied.

See also: Chrome: Vulnerabilities allow hackers to execute arbitrary code

Type Confusion vulnerabilities, such as those patched in Chrome, are a type of security vulnerability that occurs in software applications when code manipulates data using an incorrect or incompatible data type. This can lead to unexpected program behavior, as well as serious security issues, such as arbitrary code execution by attackers. Typically, Type Confusion vulnerabilities are exploited during memory attacks, where the attacker attempts to access or modify areas of memory that are not normally allowed. Proper use of type handling and careful data validation are critical to protecting systems against these types of attacks.

Source: cybersecuritynews

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS