Researchers have discovered a serious “Type Confusion” security flaw recently identified in Google Chrome.

The vulnerability, known as CVE-2024-12053, could allow attackers to execute remote malicious code, putting systems and sensitive user data at risk.
The discovery was made on November 14, 2024 by researchers “gal1ium” and “chluo,” who received a $8,000 reward for their contribution. Google responded immediately, fixing the issue in the latest version of Chrome (131.0.6778.108/.109 for Windows and Mac, and 131.0.6778.108 for Linux).
Read also: Chrome: Code update for Type Confusion vulnerabilities
What is the “Type Confusion” security flaw?
“Type Confusion” vulnerabilities in Google Chrome occur when a program allocates memory for a specific data type but incorrectly treats it as a different type. In the case of CVE-2024-12053, the vulnerability could be exploited to execute malicious code, allowing unauthorized access to systems and user data.
Google's reaction
This critical security patch is part of a broader update that covers a total of four security issues. While Google has not disclosed details of attacks exploiting this vulnerability, it is common for Google to withhold such information until more users are aware, thereby reducing the risk of exploitation.
The Chrome security team emphasized the importance of internal security procedures, which include extensive security audits, fuzzing, and the use of advanced tools like AddressSanitizer and MemorySanitizer. These initiatives help detect and fix bugs early before they reach the general public.
See more: Linux Kernel 6.13 released
What should you do?

Chrome users are urged to update their browser immediately. While updates are usually done automatically, you can check manually by going to “Settings” and selecting “About Google Chrome.”
This incident highlights the importance of promptly applying security updates and staying vigilant against ever-evolving cyber threats. Users should remain vigilant, avoiding suspicious links and untrusted downloads.
Read also: Google Chrome fixed critical vulnerabilities
Over the next few days, as the update becomes available to everyone, timely action is key to protecting your systems and data.
Source: cybersecuritynews
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
