Article Details
Scrape Timestamp (UTC): 2024-05-10 10:28:47.765
Source: https://thehackernews.com/2024/05/chrome-zero-day-alert-update-your.html
Original Article Text
Click to Toggle View
Chrome Zero-Day Alert — Update Your Browser to Patch New Vulnerability. Google on Thursday released security updates to address a zero-day flaw in Chrome that it said has been actively exploited in the wild. Tracked as CVE-2024-4671, the high-severity vulnerability has been described as a case of use-after-free in the Visuals component. It was reported by an anonymous researcher on May 7, 2024. Use-after-free bugs, which arise when a program references a memory location after it has been deallocated, can lead to any number of consequences, ranging from a crash to arbitrary code execution. "Google is aware that an exploit for CVE-2024-4671 exists in the wild," the company said in a terse advisory without revealing additional specifics of how the flaw is being weaponized in real-world attacks or the identity of the threat actors behind them. With the latest development, Google has addressed two actively exploited zero-days in Chrome since the start of the year. Earlier this January, the tech giant patched an out-of-bounds memory access issue in the V8 JavaScript and WebAssembly engine (CVE-2024-0519, CVSS score: 8.8) that could result in a crash. Users are recommended to upgrade to Chrome version 124.0.6367.201/.202 for Windows and macOS, and version 124.0.6367.201 for Linux to mitigate potential threats. Users of Chromium-based browsers such as Microsoft Edge, Brave, Opera, and Vivaldi are also advised to apply the fixes as and when they become available.
Daily Brief Summary
Google has released security updates for Chrome to address a zero-day vulnerability identified as CVE-2024-4671.
The vulnerability relates to a use-after-free issue in Chrome's Visuals component and has been exploited actively.
An anonymous researcher reported the flaw on May 7, 2024.
Use-after-free vulnerabilities can cause a range of issues, from system crashes to arbitrary code execution.
The existence of an exploit for CVE-2024-4671 in the wild has been confirmed by Google, though details of the attacks and attackers remain undisclosed.
This is the second zero-day vulnerability Google has addressed in Chrome in 2024, following a previous patch in January.
Chrome users are advised to update to the latest versions to prevent attacks: 124.0.6367.201/.202 for Windows and macOS, and 124.0.6367.201 for Linux.
Users of other Chromium-based browsers are also recommended to update their software as patches become available.