Security News > 2024 > January > Google fixes actively exploited Chrome zero-day (CVE-2024-0519)
In the new stable release of the Chrome browser, Google has fixed three security vulnerabilities affecting the V8 engine, including one zero-day with an existing exploit.
V8 is an open-source JavaScript and WebAssembly engine developed by the Chromium Project for Chromium and Google Chrome web browsers.
"Google is aware of reports that an exploit for CVE-2024-0519 exists in the wild," the Chrome team says.
The other two V8 engine flaws patched in this latest version of Chrome for Mac, Linux and Windows and Android are CVE-2024-0517 and CVE-2024-0518.
Chrome users that have set Chrome to update automatically don't need to take action, but those who update it manually should do it as soon as possible.
Since Microsoft Edge is based on Chromium, Microsoft has announced they are working on releasing a security patch.
News URL
https://www.helpnetsecurity.com/2024/01/17/cve-2024-0519/
Related news
- New tool bypasses Google Chrome’s new cookie encryption system (source)
- Google’s AI Tool Big Sleep Finds Zero-Day Vulnerability in SQLite Database Engine (source)
- Google fixes two Android zero-days used in targeted attacks (source)
- Google says “Enhanced protection” feature in Chrome now uses AI (source)
- Google Chrome’s AI feature lets you quickly check website trustworthiness (source)
- Google says new scam protection feature in Chrome uses AI (source)
- Google Chrome uses AI to analyze pages in new scam detection feature (source)
Related Vulnerability
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2024-01-16 | CVE-2024-0519 | Out-of-bounds Write vulnerability in multiple products Out of bounds memory access in V8 in Google Chrome prior to 120.0.6099.224 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | 8.8 |
2024-01-16 | CVE-2024-0518 | Type Confusion vulnerability in multiple products Type confusion in V8 in Google Chrome prior to 120.0.6099.224 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | 8.8 |
2024-01-16 | CVE-2024-0517 | Out-of-bounds Write vulnerability in multiple products Out of bounds write in V8 in Google Chrome prior to 120.0.6099.224 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | 8.8 |