Article Details

Scrape Timestamp (UTC): 2024-05-14 13:55:43.688

Source: https://thehackernews.com/2024/05/new-chrome-zero-day-vulnerability-cve.html

Original Article Text

Click to Toggle View

New Chrome Zero-Day Vulnerability CVE-2024-4761 Under Active Exploitation. Google on Monday shipped emergency fixes to address a new zero-day flaw in the Chrome web browser that has come under active exploitation in the wild. The high-severity vulnerability, tracked as CVE-2024-4761, is an out-of-bounds write bug impacting the V8 JavaScript and WebAssembly engine. It was reported anonymously on May 9, 2024. Out-of-bounds write bugs could be typically exploited by malicious actors to corrupt data, or induce a crash or execute arbitrary code on compromised hosts. "Google is aware that an exploit for CVE-2024-4761 exists in the wild," the tech giant said. Additional details about the nature of the attacks have been withheld to prevent more threat actors from weaponizing the flaw. The disclosure comes merely days after the company patched CVE-2024-4671, a use-after-free vulnerability in the Visuals component that has been exploited in real-world attacks. With the latest fix, Google has addressed a total of six zero-days since the start of the year, three of which were demonstrated at the Pwn2Own hacking contest in Vancouver in March - Users are recommended to upgrade to Chrome version 124.0.6367.207/.208 for Windows and macOS, and version 124.0.6367.207 for Linux to mitigate potential threats. Users of Chromium-based browsers such as Microsoft Edge, Brave, Opera, and Vivaldi are also advised to apply the fixes as and when they become available.

Daily Brief Summary

MALWARE // Google Issues Emergency Patch for New Chrome Zero-Day Exploit

Google has released emergency updates to counter a newly discovered zero-day flaw in Chrome, labeled CVE-2024-4761, which is currently being exploited.

The vulnerability is an out-of-bounds write error in the V8 JavaScript and WebAssembly engine, reported anonymously on May 9, 2024.

This type of vulnerability can be exploited to corrupt data, cause system crashes, or execute unauthorized code on affected devices.

The tech giant has confirmed the live exploitation of this flaw, although specific details of the attacks remain undisclosed to avoid further misuse.

The flaw was addressed shortly after the repair of another exploited vulnerability (CVE-2024-4671) in the Chrome Visuals component.

Since the beginning of the year, Google has remedied six zero-days, with three exposed during the Pwn2Own event in March 2024.

Updates for Chrome are now available in versions 124.0.6367.207/.208 for Windows and macOS and version 124.0.6367.207 for Linux.

Users of other Chromium-based browsers, such as Microsoft Edge and Brave, are advised to update their software as patches become available.