ZeroHour
Security Affairspublished ()ingested @securityaffairs

Google fixed a critical vulnerability in Chrome browser

criticalVulnerability exploited in the wildimportance 60CVE-2024-10487CVE-2024-10488CVE-2024-7965

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2024-10487
+1 in the same advisory: …10488
Out of bounds write in Dawn in Google Chrome prior to 130.0.6723.92 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page.

Out of bounds write in Dawn in Google Chrome prior to 130.0.6723.92 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: Critical)

NVD description · AI analysis pending
8.8<1%
  • google chrome
CVE-2024-7965
Chromium V8 heap corruption flaw (CVE-2024-7965) actively exploited in Chrome and Edge

CVE-2024-7965 is an inappropriate implementation in the V8 JavaScript engine used by Google Chrome and other Chromium-based browsers, rated High severity (CVSS 3.1: 8.8) and tracked under CWE-787 (out-of-bounds write). It is triggered remotely when a user visits a crafted HTML page; the attack requires no privileges but does require user interaction, and successful exploitation potentially yields heap corruption with high impact on confidentiality, integrity and availability — in practice, compromise of the browser process. All Google Chrome installs prior to 128.0.6613.84 are affected, and the CISA/CPE data also places Microsoft's Chromium-based Edge in scope. The flaw is confirmed exploited in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on 2024-08-28 and Google warned of active exploitation, with EPSS assigning an 18.5% next-30-day exploitation probability (97th percentile), though no public proof-of-concept code is known. Related coverage notes Google patched this alongside a string of actively exploited Chrome zero-days in August 2024.

Do: Update Google Chrome to 128.0.6613.84 or later (Menu > Help > About Chrome, or enforce this version baseline via enterprise browser-update policies) and install Microsoft's corresponding Edge update that incorporates the Chromium V8 fix; other Chromium-based browsers should be updated to their upstream 128.0.6613.84-era builds. Because this is a KEV-listed bug exploited via malicious web pages and requires only that a user visit an attacker-crafted HTML page, treat browser patching as urgent and verify fleet-wide versions rather than relying on auto-update. Per the CISA KEV required action, apply the vendor mitigations or discontinue use of affected builds if patching is unavailable.

8.819% KEV
  • google chrome prior to 128.0.6613.84
  • google chromium (V8 engine) V8 in Chromium prior to the 128.0.6613.84 fix (CISA affected component: 'Google Chromium V8')
  • microsoft edge chromium Chromium-based Edge builds predating Microsoft's update incorporating the Chromium 128.0.6613.84 V8 fix (fixed Edge build number not specified in source data)
massorder of billions of users (Chrome alone has on the order of 3 billion+ active users, with Edge Chromium adding hundreds of millions more on unpatched builds)
Full article310 words · extracted from securityaffairs.com · click to collapse

Google addressed a critical vulnerability in its Chrome browser, tracked as CVE-2024-10487, which was reported by Apple.

Google has patched a critical Chrome vulnerability, tracked as CVE-2024-10487, reported by Apple Security Engineering and Architecture (SEAR) on October 23, 2024.

The vulnerability is an out-of-bounds write issue that resides in the Dawn implementation.

Dawn is an open-source and cross-platform implementation of the WebGPU standard. More precisely it implements webgpu. h that is a one-to-one mapping with the WebGPU IDL. Dawn is meant to be integrated as part of a larger system and is the underlying implementation of WebGPU in Chromium.

It’s unclear if the vulnerability has been actively exploited in attacks in the wild.

Google also addressed a high-severity vulnerability, tracked as CVE-2024-10488, in WebRTC. The vulnerability is a use-after-free issue that resides in the WebRTC, it was reported by Cassidy Kim(@cassidy6564) on October 18, 2024.

Google addressed both issues with the release of Chrome 130. 

“The Stable channel has been updated to 130.0.6723.91/.92 for Windows, Mac and 130.0.6723.91 for Linux which will roll out over the coming days/weeks. A full list of changes in this build is available in the Log.” reads the advisory. “The Extended Stable channel has been updated to 130.0.6723.92 for Windows and Mac which will roll out over the coming days/weeks. “

As usual, Google states that bug details and links remain restricted until most users have applied the fix.

Google Chrome is a privileged target of threat actors, in many cases, attackers exploited zero-days in the popular browser.

In August, Google released a security update to address a new Chrome zero-day vulnerability, tracked as CVE-2024-7965 (CVSS score 8.8), that is actively exploited.

The vulnerability is an Inappropriate implementation issue that resides in Chrome’s V8 JavaScript engine.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, Google Chrome)



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/170395/security/google-fixed-critical-chrome-flaw.html