ZeroHour
Help Net Securitypublished ()ingested @zeljkazorz

Google fixes actively exploited Chrome zero-day (CVE-2024-0519)

criticalExploit / PoC exploited in the wildimportance 60CVE-2024-0519CVE-2024-0517CVE-2024-0518

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2024-0517
+1 in the same advisory: …0518
Out of bounds write in V8 in Google Chrome prior to 120.0.6099.224 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

Out of bounds write in V8 in Google Chrome prior to 120.0.6099.224 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

NVD description · AI analysis pending
8.822%
  • google chrome
  • google fedora
CVE-2024-0519
Out-of-Bounds Memory Access in Google Chrome/Chromium V8 (Actively Exploited)

Google Chrome's V8 JavaScript engine, in versions prior to 120.0.6099.224, contains an out-of-bounds memory access flaw (CWE-787 out-of-bounds write / CWE-125 out-of-bounds read) that is triggered when a user visits a specially crafted HTML page. A remote attacker who lures a victim to such a page can potentially corrupt the heap and execute code in the context of the browser. Successful exploitation could lead to exposure of sensitive information, data tampering, or denial of service (CVSS 3.1: 8.8 High; user interaction is required). Anyone running a vulnerable Chrome/Chromium build is affected, including downstream products that embed V8, such as Fedora's Chromium/Chrome packages and Couchbase Server. The flaw is being actively exploited in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on 2024-01-17, and news coverage describes it as one of Google's actively exploited Chrome zero-days patched in January 2024.

Do: Update Google Chrome to 120.0.6099.224 or later (and restart the browser so the new version is fully loaded); verify fleet versions via Chrome's version reporting if managing enterprise deployments. Fedora users should install the updated chromium/chrome packages via the distribution's update channel, and Couchbase Server operators should apply the vendor's guidance. Because the flaw is on CISA's KEV catalog, federal and other regulated environments are required to apply vendor mitigations promptly; the only effective mitigation is patching, as no public PoC or alternate workaround is documented.

8.84% KEV
  • Google Chrome / Chromium V8 JavaScript engine prior to 120.0.6099.224
  • Fedora Project Fedora (Chromium/Chrome packages embedding affected V8)
  • Couchbase Server (embeds affected V8)
massbillions of users (Chrome holds roughly 65% of desktop browser share with over 3 billion users, and any browser prior to 120.0.6099.224 was vulnerable)
Full article259 words · extracted from helpnetsecurity.com · click to collapse

In the new stable release of the Chrome browser, Google has fixed three security vulnerabilities affecting the V8 engine, including one zero-day (CVE-2024-0519) with an existing exploit.

CVE-2024-0519

About CVE-2024-0519

V8 is an open-source JavaScript and WebAssembly engine developed by the Chromium Project for Chromium and Google Chrome web browsers.

CVE-2024-0519 is an (obviously exploitable) out of bounds memory access that, as noted by NIST, “allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.”

The vulnerability has been flagged by an anonymous researcher.

“Google is aware of reports that an exploit for CVE-2024-0519 exists in the wild,” the Chrome team says.

The other two V8 engine flaws patched in this latest version of Chrome for Mac, Linux and Windows and Android are CVE-2024-0517 (an out of bounds write bug) and CVE-2024-0518 (a type confusion flaw).

Chrome users that have set Chrome to update automatically don’t need to take action, but those who update it manually should do it as soon as possible. (With zero-days in Chrome getting regularly exploited, opting for automatic updates is not a bad idea.)

Fixes in other Chromium-based browsers

Since Microsoft Edge is based on Chromium, Microsoft has announced they are working on releasing a security patch.

“It’s worth highlighting that Microsoft Edge’s enhanced security mode feature mitigates this vulnerability. You can opt-in into this security feature and have peace of mind that Microsoft Edge is protecting you against this exploit,” they added.

Other popular Chromium-based browsers such as Brave, Opera, and Vivaldi will likely include those fixes soon.

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2024/01/17/cve-2024-0519/