ZeroHour
The Hacker Newspublished ()ingested @TheHackersNews

Two New Chrome 0-Days Under Active Attacks

criticalExploit / PoC exploited in the wildimportance 60CVE-2020-16013CVE-2020-16017CVE-2020-16009

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2020-16009
Type Confusion in Google Chromium V8 Engine Enables RCE via Crafted HTML Pages

CVE-2020-16009 is a type confusion vulnerability (CWE-843) in the V8 JavaScript engine used by Google Chromium, which can lead to heap corruption (CWE-787). A remote attacker triggers it by getting a user to load a specially crafted HTML page, such as via a malicious or compromised website. Successful exploitation corrupts the heap and can potentially allow the attacker to execute code in the context of the affected browser. Any Chromium-based browser or application embedding V8 is affected, including Google Chrome, Microsoft Edge, and Opera, meaning the affected population is effectively the entire Chromium user base worldwide. CISA added the flaw to its Known Exploited Vulnerabilities catalog on 2021-11-03, confirming exploitation in the wild, with an EPSS probability of 48.3% (99th percentile); ransomware use is unknown and no public PoC is known.

Do: Apply the vendor update per CISA's required action: update all Chromium-based browsers (Chrome, Edge, Opera, and derivatives) to the latest stable releases from each vendor and restart browsers afterward. Inventory any embedded or packaged Chromium/V8 runtimes in other applications and update them as their maintainers ship fixes. Given confirmed in-the-wild exploitation and high EPSS, prioritize patching endpoints used for web browsing by high-risk users first.

8.848% KEV PoC ×2
  • Google Chromium V8
  • Google Chrome (Chromium-based browser)
  • Microsoft Edge (Chromium-based browser)
  • +1 more
mass≈3+ billion browser users/installations (Chromium is the world's dominant browser engine)
CVE-2020-16013
Heap Corruption in Google Chrome V8 Engine (CVE-2020-16013) Under Active Attack

Google Chrome's V8 JavaScript engine contained an inappropriate implementation (CWE-787, out-of-bounds write) that could corrupt the browser's heap. A remote attacker triggers the flaw by getting a user to open a crafted HTML page, since the bug is reached through JavaScript processing in the browser (user interaction is required, per the CVSS vector). Successful exploitation could allow the attacker to execute code in the browser with high confidentiality, integrity and availability impact, consistent with the 8.8 CVSS score. All Google Chrome users running versions prior to 86.0.4240.198 were affected, as are Chromium-based builds relying on the same V8 code. The flaw was a zero-day under active attack when Google patched it in the November 2020 stable-channel update; it was added to CISA KEV on 2021-11-03 (ransomware use unknown), carries a 2.8% EPSS (85th percentile), and no public PoC is known.

Do: Upgrade Google Chrome to 86.0.4240.198 or later on all endpoints and verify the running version at chrome://version; this is the November 2020 stable-channel release that patched the actively exploited zero-day. Chromium-based browsers (e.g., Edge, Brave, Opera, Vivaldi) inherit the V8 fix through their own upstream updates, so ensure the latest available release is deployed there as well. As a CISA KEV entry, the required action is to apply vendor updates per vendor instructions within the KEV patching deadline.

8.83% KEV
  • google chrome all versions prior to 86.0.4240.198 (fixed in 86.0.4240.198)
  • google chromium v8 (javascript engine) V8 as bundled in Chrome/Chromium prior to 86.0.4240.198
massbillions of users/installations (Chrome is the world's dominant browser, roughly two-thirds desktop market share)
CVE-2020-16017
Use-After-Free Sandbox Escape in Google Chrome

CVE-2020-16017 is a use-after-free vulnerability in the site isolation component of Google Chrome, fixed in version 86.0.4240.198. It is triggered by a crafted HTML page and requires the attacker to have already compromised the renderer process, for example via a chained renderer bug. By exploiting the flaw, the attacker can escape Chrome's renderer sandbox and gain code execution with broader privileges on the host system. Any user running an affected Chrome release prior to 86.0.4240.198 is exposed. The flaw was a zero-day exploited in active attacks at the time of disclosure, is listed in CISA's Known Exploited Vulnerabilities catalog (added 2021-11-03), and Google shipped the fix as an urgent stable-channel update.

Do: Update Google Chrome to version 86.0.4240.198 or later and verify the installed version in the browser's About dialog; enable automatic updates so renderer/sandbox fixes are applied promptly. Administrators should audit managed endpoints for outdated Chrome builds and prioritize updates given the confirmed in-the-wild exploitation and KEV listing; the required action per CISA is to apply updates per vendor instructions.

9.63% KEV
  • google chrome all versions prior to 86.0.4240.198
masson the order of a billion or more Chrome users (unpatched installs at disclosure; currently, mainly outdated/frozen Chrome installs)
Full article297 words · extracted from thehackernews.com · click to collapse

Ravie LakshmananNov 12, 2020

Google has patched two more zero-day flaws in the Chrome web browser for desktop, making it the fourth and fifth actively exploited vulnerabilities addressed by the search giant in recent weeks.

The company released 86.0.4240.198 for Windows, Mac, and Linux, which it said will be rolling out over the coming days/weeks to all users.

Tracked as CVE-2020-16013 and CVE-2020-16017, the flaws were discovered and reported to Google by "anonymous" sources, unlike previous cases, which were uncovered by the company's Project Zero elite security team.

Google acknowledged that exploits for both the vulnerabilities exist in the wild but stopped short of sharing more specifics to allow a majority of users to install the fixes.

According to the release notes, the two flaws are:

  • CVE-2020-16013: An "inappropriate implementation" of its V8 JavaScript rendering engine was reported on November 9.
  • CVE-2020-16017: An use-after-free memory corruption issue in Chrome's site isolation feature was reported on November 7.

It's worth noting that the zero-day it patched last week, CVE-2020-16009, also concerned an inappropriate implementation of V8, leading to remote code execution. It's not immediately clear if the two flaws are related.

Over the last week, Google disclosed a number of actively exploited zero-day flaws targeting Chrome, Windows, and Apple's iOS and macOS, and while it appears that some of these issues were strung together to form an exploit chain, the company is yet to reveal key details about who may have been using them and who were the intended targets.

It's advised that users update their devices to the latest Chrome version to mitigate the risk associated with the two flaws.

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.

Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2020/11/two-new-chrome-0-days-under-active.html