Replace Chrome Browser Now: 4th Zero-Day Exploit Found in Might 2024

Might 24, 2024NewsroomVulnerability / Browser Safety

Google on Thursday rolled out fixes to handle a high-severity safety flaw in its Chrome browser that it stated has been exploited within the wild.

Assigned the CVE identifier CVE-2024-5274, the vulnerability pertains to a sort confusion bug within the V8 JavaScript and WebAssembly engine. It was reported by Clément Lecigne of Google’s Menace Evaluation Group and Brendon Tiszka of Chrome Safety on Might 20, 2024.

Kind confusion vulnerabilities happen when a program makes an attempt to entry a useful resource with an incompatible sort. It could possibly have severe penalties because it permits risk actors to carry out out-of-bounds reminiscence entry, trigger a crash, and execute arbitrary code.

The event marks the fourth zero-day that Google has patched because the begin of the month after CVE-2024-4671, CVE-2024-4761, and CVE-2024-4947.

Cybersecurity

The tech large didn’t disclose extra technical particulars concerning the flaw, however acknowledged that it “is aware that an exploit for CVE-2024-5274 exists in the wild.” It is not clear if the shortcoming is a patch bypass for CVE-2024-4947, which can be a sort confusion bug in V8.

With the most recent repair, Google has resolved a complete of eight zero-days have been resolved by Google in Chrome because the begin of the yr –

Customers are advisable to improve to Chrome model 125.0.6422.112/.113 for Home windows and macOS, and model 125.0.6422.112 for Linux to mitigate potential threats.

Customers of Chromium-based browsers equivalent to Microsoft Edge, Courageous, Opera, and Vivaldi are additionally suggested to use the fixes as and once they change into out there.

Discovered this text attention-grabbing? Comply with us on Twitter and LinkedIn to learn extra unique content material we publish.

Recent articles

Astaroth Banking Malware Resurfaces in Brazil by way of Spear-Phishing Assault

Oct 16, 2024Ravie LakshmananCyber Assault / Banking Trojan A brand...

GitHub Patches Crucial Flaw in Enterprise Server Permitting Unauthorized Occasion Entry

Oct 16, 2024Ravie LakshmananEnterprise Safety / Vulnerability GitHub has launched...

New Linux Variant of FASTCash Malware Targets Fee Switches in ATM Heists

Oct 15, 2024Ravie LakshmananMonetary Fraud / Linux North Korean risk...

Amazon says 175 million buyer now use passkeys to log in

Amazon has seen large adoption of passkeys for the...