Google has released security updates to fix the first Chrome zero-day vulnerability exploited in the wild since the start of the year.
The company fixed the zero-day for users in the Stable Desktop channel, with patched versions rolling out worldwide to Windows, Mac, and Linux users less than a week after being reported to Google.
Although Google says the security update could take days or weeks to reach all impacted users, it was available immediately when BleepingComputer checked for updates today.
Those who prefer not to update their web browser manually can rely on Chrome to automatically check for new updates and install them after the next launch.
The high-severity zero-day vulnerability is due to a high-severity out-of-bounds memory access weakness in the Chrome V8 JavaScript engine, which attackers can exploit to gain access to data beyond the memory buffer, providing them access to sensitive information or triggering a crash.
Besides unauthorized access to out-of-bounds memory, CVE-2024-0519 could also be exploited to bypass protection mechanisms such as ASLR to make it easier to achieve code execution via another weakness.
While Google knows of CVE-2024-0519 zero-day exploits used in attacks, the company has yet to share further details regarding these incidents.
Today, Google also patched V8 out-of-bounds write and type confusion flaws, allowing for arbitrary code execution on compromised devices.
Last year, Google fixed eight Chrome zero-day bugs exploited in attacks tracked as CVE-2023-7024, CVE-2023-6345, CVE-2023-5217, CVE-2023-4863, CVE-2023-3079, CVE-2023-4762, CVE-2023-2136, and CVE-2023-2033.
Like CVE-2023-4762, were tagged as zero-days used to deploy spyware on vulnerable devices belonging to high-risk users, including journalists, opposition politicians, and dissidents, several weeks after the company released patches.
Google Chrome emergency update fixes 7th zero-day exploited in 2023.
Google fixes 8th Chrome zero-day exploited in attacks this year.
Apple emergency updates fix recent zero-days on older iPhones.
Latest Adblock update causes massive YouTube performance hit.
Ivanti Connect Secure zero-days now under mass exploitation.
This Cyber News was published on www.bleepingcomputer.com. Publication date: Tue, 16 Jan 2024 19:15:30 +0000