Google fixed the first actively exploited Chrome zero
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2024-0517 +1 in the same advisory: …0518 | Out of bounds write in V8 in Google Chrome prior to 120.0.6099.224 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. Out of bounds write in V8 in Google Chrome prior to 120.0.6099.224 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) NVD description · AI analysis pending | 8.8 | 22% |
| — | ||
| CVE-2024-0519 | Out-of-Bounds Memory Access in Google Chrome/Chromium V8 (Actively Exploited) Google Chrome's V8 JavaScript engine, in versions prior to 120.0.6099.224, contains an out-of-bounds memory access flaw (CWE-787 out-of-bounds write / CWE-125 out-of-bounds read) that is triggered when a user visits a specially crafted HTML page. A remote attacker who lures a victim to such a page can potentially corrupt the heap and execute code in the context of the browser. Successful exploitation could lead to exposure of sensitive information, data tampering, or denial of service (CVSS 3.1: 8.8 High; user interaction is required). Anyone running a vulnerable Chrome/Chromium build is affected, including downstream products that embed V8, such as Fedora's Chromium/Chrome packages and Couchbase Server. The flaw is being actively exploited in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on 2024-01-17, and news coverage describes it as one of Google's actively exploited Chrome zero-days patched in January 2024. Do: Update Google Chrome to 120.0.6099.224 or later (and restart the browser so the new version is fully loaded); verify fleet versions via Chrome's version reporting if managing enterprise deployments. Fedora users should install the updated chromium/chrome packages via the distribution's update channel, and Couchbase Server operators should apply the vendor's guidance. Because the flaw is on CISA's KEV catalog, federal and other regulated environments are required to apply vendor mitigations promptly; the only effective mitigation is patching, as no public PoC or alternate workaround is documented. | 8.8 | 4% | KEV |
| massbillions of users (Chrome holds roughly 65% of desktop browser share with over 3 billion users, and any browser prior to 120.0.6099.224 was vulnerable) |
Full article231 words · extracted from securityaffairs.com · click to collapse

Google has addressed the first Chrome zero-day vulnerability of the year that is actively being exploited in the wild.
Google has released security updates to address the first Chrome zero-day vulnerability of the year that is actively being exploited in the wild.
The high-serverity vulnerability, tracked as CVE-2024-0519, is an out of bounds memory access in the Chrome JavaScript engine. The flaw was reported by Anonymous on January 11, 2024.
“The Stable channel has been updated to 120.0.6099.234 for Mac and 120.0.6099.224 for Linux and 120.0.6099.224/225 to Windows which will roll out over the coming days/weeks.” reads the security advisory published by the IT giant. “Google is aware of reports that an exploit for CVE-2024-0519 exists in the wild.”
A remote attacker can exploit the flaw by tricking a user into visiting a crafted HTML page to potentially exploit heap corruption.
As usual, Google did not share details of the attacks that exploited the CVE-2024-0519 zero-day in the wild.
Google also fixed the following vulnerabilities:
- [$16000][1515930] High CVE-2024-0517: Out of bounds write in V8. The flaw has been reported by Toan (suto) Pham of Qrious Secure on 2024-01-06
- [$1000][1507412] High CVE-2024-0518: Type Confusion in V8. The flaw has been reported by Ganjiang Zhou(@refrain_areu) of ChaMd5-H1 team on 2023-12-03
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – hacking, Chrome zero-day)
Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/157600/security/google-first-chrome-zero-day-2024.html