Google fixes yet another Chrome zero-day exploited in the wild (CVE-2024-5274)
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2024-5274 | Google Chrome V8 Type Confusion Allows In-Sandbox RCE via Crafted HTML Pages CVE-2024-5274 is a type confusion flaw (CWE-843) in the V8 JavaScript engine of Google Chrome prior to 125.0.6422.112. A remote attacker can trigger it by persuading a user to open or interact with a crafted HTML page. Successful exploitation allows the attacker to execute arbitrary code inside the browser's sandbox, and the scope-changed CVSS scoring indicates potential impact beyond the browser process itself. Anyone running an affected Chrome or Chromium build, including Chromium-derived distributions such as Fedora's Chromium package, is exposed. The flaw was added to CISA's KEV on 2024-05-28, a public PoC reference exists, and related news reports describe it as actively exploited in the wild. Do: Upgrade Google Chrome to 125.0.6422.112 or later and confirm the build via chrome://version; Fedora users and users of Chromium-derived browsers should install the corresponding updated packages from their vendor. Because the flaw is listed in CISA KEV, federal agencies and targeted organizations must apply the vendor fix or discontinue use per the required action, and all users should avoid untrusted web content until patched. | 9.6 | 7% | KEV PoC |
| masson the order of billions of users (Chrome has 3+ billion users and roughly two-thirds desktop browser share) |
Full article230 words · extracted from helpnetsecurity.com · click to collapse
For the eighth time this year, Google has released an emergency update for its Chrome browser that fixes a zero-day vulnerability (CVE-2024-5274) with an in-the-wild exploit.

About CVE-2024-5274
As per usual, Google keeps technical details of the vulnerability under wraps. All they tell us is that the vulnerability is a type confusion bug in V8, Chrome’s JavaScript and WebAssembly engine.
“Google is aware that an exploit for CVE-2024-5274 exists in the wild,” the company says.
The fact that the vulnerability has been reported by security researcher Clément Lecigne of Google’s Threat Analysis Group (TAG) and Brendon Tiszka of its Chrome Security team seems to indicate that the zero-day is also being actively exploited by attackers.
Updates are already available
The zero-day has been fixed in Chrome 125.0.6422.112/.113 (for Windows and Mac) and 125.0.6422.112 (for Linux).
Depending on the operating system you use and whether you have disabled the auto-updating feature (for the Enterprise version of Chrome) or not, you can implement the update manually or you can close and reopen the browser and Google will do that for you.
Other Chromium-based browsers are expected to implement the fix soon, and Vivaldi already has.
Earlier this month, Google fixed three exploited zero-days in less than a week.

Subscribe to our breaking news e-mail alert to never miss out on the latest breaches, vulnerabilities and cybersecurity threats. Subscribe here!

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2024/05/24/cve-2024-5274/