ZeroHour
Security Affairspublished ()ingested @securityaffairs

WeChat users targeted by hackers using recently disclosed Chromium exploit

criticalExploit / PoCimportance 60CVE-2021-21220

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2021-21220
Out-of-Bounds Write in Google Chrome V8 Enables Heap Corruption and Potential RCE

CVE-2021-21220 is an insufficient input validation flaw (CWE-787, out-of-bounds write) in the V8 JavaScript engine used by Google Chrome, affecting Chrome versions prior to 89.0.4389.128. A remote attacker can trigger the flaw by persuading a user to open a crafted HTML page, causing V8 to mishandle untrusted input and corrupt the heap. Successful exploitation can lead to heap corruption and potential remote code execution in the browser, with no privileges required beyond user interaction. The flaw affects Chrome and Chromium-based builds that ship the vulnerable V8 engine, including Fedora's Chromium package. It was exploited in the wild as a zero-day before the April 2021 fix, is listed in CISA's Known Exploited Vulnerabilities catalog (added 2021-11-03), and related reporting notes attacks using the disclosed Chromium exploit against WeChat users.

Do: Update Google Chrome to version 89.0.4389.128 or later (ideally the current stable release); Fedora users should apply the updated Chromium package from their distribution repositories. Because the flaw is in the CISA KEV catalog, federal and KEV-bound organizations must patch per vendor instructions, and users of other Chromium-based browsers should verify their underlying V8/Chromium version has incorporated the fix.

8.870% KEV PoC ×2
  • google chrome (Chromium V8 engine) prior to 89.0.4389.128
  • fedoraproject fedora (Chromium/V8 build)
massbillions of Chrome users (Chrome holds roughly 60%+ of desktop browser market share)
Full article309 words · extracted from securityaffairs.com · click to collapse

Threat actors used the Chrome exploit publicly disclosed last week in attacks aimed at WeChat users in China, researchers warn.

China-based firm Qingteng Cloud Security, reported that threat actors weaponized the recently disclosed Chrome exploit to target WeChat users in China. According to the researchers, the attacks only targeted users of the WeChat Windows app. The security firm did not reveal which of the two PoC codes released last week were employed in the attacks.

Attackers are sharing specially crafted links with WeChat users, upon clicking them, a JavaScript code will execute a shellcode on their underlying operating systems.

Last week, two distinct researchers released exploit codes for two new Chromium zero-day remote code execution exploit affecting Google Chrome, Microsoft Edge, and likely other Chromium-based browsers.

The WeChat Windows client was impacted by the issues because it leverages the Chromium browser engine to manage links within the application.

Both remote code execution vulnerabilities disclosed last week could not escape Chromium’s sandbox, which means that attackers have chained them with a sandbox escape exploit to executing arbitrary code on the underlying system.

Anyway, as reported in a post by The Record, applications that don’t use a sandbox mechanism could expose the underlying OS to the risk of a hack.

Qingteng shared its findings with Tencent, the Chinese giant that developed WeChat, which updated the Chromium engine used by the application.

The good news is that both flaws have been already addressed by maintainers of the Chromium project and developers of major browsers are applying them.

Chrome has only fixed one of the flaws (CVE-2021-21220), while Microsoft Edge fixed both exploits.

If you want to receive the weekly Security Affairs Newsletter for free subscribe here.

Follow me on Twitter: @securityaffairs and Facebook

[adrotate banner=”9″][adrotate banner=”12″]

Pierluigi Paganini

(SecurityAffairs – hacking, Chrome)

[adrotate banner=”5″]

[adrotate banner=”13″]



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/117017/hacking/wechat-chromium-bug-attack.html