Article Details

Scrape Timestamp (UTC): 2024-05-10 10:28:47.765

Source: https://thehackernews.com/2024/05/chrome-zero-day-alert-update-your.html

Original Article Text

Click to Toggle View

Chrome Zero-Day Alert — Update Your Browser to Patch New Vulnerability. Google on Thursday released security updates to address a zero-day flaw in Chrome that it said has been actively exploited in the wild. Tracked as CVE-2024-4671, the high-severity vulnerability has been described as a case of use-after-free in the Visuals component. It was reported by an anonymous researcher on May 7, 2024. Use-after-free bugs, which arise when a program references a memory location after it has been deallocated, can lead to any number of consequences, ranging from a crash to arbitrary code execution. "Google is aware that an exploit for CVE-2024-4671 exists in the wild," the company said in a terse advisory without revealing additional specifics of how the flaw is being weaponized in real-world attacks or the identity of the threat actors behind them. With the latest development, Google has addressed two actively exploited zero-days in Chrome since the start of the year. Earlier this January, the tech giant patched an out-of-bounds memory access issue in the V8 JavaScript and WebAssembly engine (CVE-2024-0519, CVSS score: 8.8) that could result in a crash. Users are recommended to upgrade to Chrome version 124.0.6367.201/.202 for Windows and macOS, and version 124.0.6367.201 for Linux to mitigate potential threats. Users of Chromium-based browsers such as Microsoft Edge, Brave, Opera, and Vivaldi are also advised to apply the fixes as and when they become available.

Daily Brief Summary

MALWARE // Google Issues Security Patch for Chrome Zero-Day Exploit

Google has released security updates for Chrome to address a zero-day vulnerability identified as CVE-2024-4671.

The vulnerability relates to a use-after-free issue in Chrome's Visuals component and has been exploited actively.

An anonymous researcher reported the flaw on May 7, 2024.

Use-after-free vulnerabilities can cause a range of issues, from system crashes to arbitrary code execution.

The existence of an exploit for CVE-2024-4671 in the wild has been confirmed by Google, though details of the attacks and attackers remain undisclosed.

This is the second zero-day vulnerability Google has addressed in Chrome in 2024, following a previous patch in January.

Chrome users are advised to update to the latest versions to prevent attacks: 124.0.6367.201/.202 for Windows and macOS, and 124.0.6367.201 for Linux.

Users of other Chromium-based browsers are also recommended to update their software as patches become available.