Google patches Chrome zero
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2021-30551 | V8 Type Confusion Zero-Day in Google Chrome (CVE-2021-30551), Exploited in the Wild CVE-2021-30551 is a type confusion flaw (CWE-843) in the V8 JavaScript engine used by Google Chrome and Chromium, which can lead to heap corruption. An attacker triggers it by persuading a user to open a specially crafted HTML page — the browser bug requires user interaction but no privileges or authentication. Successful exploitation could allow a remote attacker to execute code or otherwise corrupt the browser process, with high impact on confidentiality, integrity, and availability (CVSS 3.1: 8.8). Anyone running Google Chrome prior to 91.0.4472.101, including Chromium-based packages such as Fedora's chromium, is affected. The flaw was exploited as a zero-day before the fix was released, with Google attributing recent Chrome zero-day attacks including this issue to campaigns against Armenian targets linked to a commercial spyware vendor, and it is listed in CISA's Known Exploited Vulnerabilities catalog. Do: Update Google Chrome to 91.0.4472.101 or later (via chrome://settings/help) and update Fedora's chromium package to the patched build, then verify the version in chrome://version. Fedora/Chromium administrators should apply vendor updates per CISA KEV guidance. Until patched, treat web browsing as a risk vector and avoid opening untrusted links, since exploitation requires loading a crafted web page. | 8.8 | 65% | KEV PoC |
| masshundreds of millions to billions of Chrome/Chromium installs worldwide (Chrome is the world's dominant browser) | |
| CVE-2021-33742 | Out-of-Bounds Write RCE in Microsoft Windows MSHTML Engine (CVE-2021-33742) A remote code execution vulnerability exists in the Microsoft Windows MSHTML Platform — the Internet Explorer/Trident rendering engine that Windows components and applications invoke to display web content — caused by an out-of-bounds write (CWE-787). An attacker triggers it by persuading a user to open attacker-controlled content, such as a crafted document or web page that causes MSHTML to render a remote URL; no privileges are required, but user interaction is needed and the attack is rated high complexity. Successful exploitation runs attacker code in the context of the logged-in user, potentially allowing installation of programs, viewing/changing/deleting data, or creating new accounts with the victim's rights. The affected range spans Windows 7, 8.1, RT 8.1, Windows 10 versions 1507 through 21H1, and Windows Server 2008 and 2012 — essentially the entire supported Windows installed base at the time of disclosure. Exploitation is confirmed in the wild: Microsoft disclosed the flaw as used in limited targeted attacks, CISA added it to the Known Exploited Vulnerabilities catalog on 2021-11-03 (ransomware use unknown), and EPSS assigns a 59.4% 30-day exploitation probability (99th percentile). Do: Apply Microsoft's security update for CVE-2021-33742, delivered via the July 2021 cumulative Windows updates (and later), to all affected Windows 7/8.1/RT 8.1/10 clients and Windows Server 2008/2012 hosts, prioritizing internet-exposed systems and per CISA's required action. Because exploitation requires user interaction, treat unsolicited documents and links with caution until systems are patched. No public proof-of-concept is known, but the KEV listing confirms real-world targeted exploitation, so assume active scanning/attacks and verify patch status across the estate. | 7.5 | 59% | KEV |
| masson the order of 1 billion+ Windows installations |
Full article291 words · extracted from therecord.media · click to collapse
Google has released an update for the Chrome browser today to fix a zero-day vulnerability the company's security team said was part of the arsenal of a "commercial exploit company." The vulnerability, tracked as CVE-2021-30551, was abused in the wild together with a Windows zero-day, tracked as CVE-2021-33742, which Microsoft patched yesterday. Shane Huntley, head of the Google Threat Analysis Group, whose team discovered the attacks, said the two zero-days were provided by the exploit broker to a nation-state, which used them for a small number of attacks against targets in Eastern Europe and the Middle East. Chrome in-the-wild vulnerability CVE-2021-30551 patched today was also from the same actor and targeting. Huntley said his team, which tracks nation-state operations and advanced threat actors using Google's considerable data insights, plans to reveal more details about the vulnerabilities in 30 days in order to give users more time to apply patches before broader technical information is available. Google's discovery is, however, not the only one. Yesterday's Microsoft Patch Tuesday also included fixes for two other Windows zero-days that were exploited via a Chrome-based delivery mechanism. Researchers from Russian security firm Kaspersky said in a report yesterday that they only managed to analyze the Windows part of the attack but not the Chrome exploit code, which currently remains unknown and unpatched. But while this Chrome attack vector remains unknown, users can update to Google Chrome v91.0.4472.101 today to protect themselves against CVE-2021-30551, the zero-day developed by the yet-to-be-identified "commercial exploit company." Chrome in-the-wild vulnerability CVE-2021-30551 is patched. Another one found by Google TAG! (@_clem1) https://t.co/SD4ZFTP5VZ
Thanks to Chrome team for also patching within 7 days.https://t.co/1RDbbuiBfY https://t.co/Ap9dEq98Cy
Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/google-patches-chrome-zero-day-linked-to-commercial-exploit-company