Article Details
Scrape Timestamp (UTC): 2024-05-15 22:36:50.469
Original Article Text
Click to Toggle View
Google patches third exploited Chrome zero-day in a week. Google has released a new emergency Chrome security update to address the third zero-day vulnerability exploited in attacks within a week. "Google is aware that an exploit for CVE-2024-4947 exists in the wild," the search giant said in a security advisory published on Wednesday. The company fixed the zero-day flaw with the release of 125.0.6422.60/.61 for Mac/Windows and 125.0.6422.60 (Linux). The new versions will roll out to all users in the Stable Desktop channel over the coming weeks. Chrome updates automatically when security patches are available. However, users can also confirm they're running the latest version by going to Chrome menu > Help > About Google Chrome, letting the update finish, and then clicking on the 'Relaunch' button to install it. Today's update was immediately available when BleepingComputer checked for new updates. The high-severity zero-day vulnerability (CVE-2024-4947) is caused by a type confusion weakness in the Chrome V8 JavaScript engine reported by Kaspersky's Vasily Berdnikov and Boris Larin. Even though such vulnerabilities generally enable threat actors to trigger browser crashes by reading or writing memory out of buffer bounds, they can also exploit them for arbitrary code execution on targeted devices. While Google confirmed the CVE-2024-4947 bug was used in attacks, the company has yet to share more details regarding these incidents. "Access to bug details and links may be kept restricted until a majority of users are updated with a fix," Google said. "We will also retain restrictions if the bug exists in a third party library that other projects similarly depend on, but haven't yet fixed." Seventh actively exploited zero-day patched in 2024 This latest Chrome vulnerability is the seventh zero-day fixed in the Google web browser since the start of the year, with the complete list of zero-days patched in 2024 including:
Daily Brief Summary
Google released an emergency update for Chrome to patch a severe zero-day vulnerability known as CVE-2024-4947, already exploited in the wild.
This marks the third zero-day exploit addressed by Google within a single week, highlighting an intensifying security threat.
The vulnerability stems from a type confusion issue in Chrome’s V8 JavaScript engine, discovered by researchers at Kaspersky.
The flaw can potentially allow attackers to execute arbitrary code on target devices by manipulating browser memory.
Chrome updates are deployed automatically, but users can manually verify and finalize the update via the browser's settings.
Given the nature of the exploit, Google restricted access to detailed bug information to prevent further abuse until most users have updated.
This recent patch is part of a broader trend, with Google fixing a total of seven actively exploited zero-days in Chrome since the onset of 2024.