ZeroHour
CyberScooppublished ()ingested @shanvav

Google releases update to fix another zero

criticalExploit / PoCimportance 60CVE-2021-21224

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2021-21224
Type Confusion RCE in Google Chrome/Chromium V8 JavaScript Engine

CVE-2021-21224 is a type confusion vulnerability (CWE-843) in V8, the JavaScript engine used by Google Chrome and Chromium. An attacker triggers it by luring a user to open a crafted HTML page, causing V8 to mishandle object types during execution. Successful exploitation yields arbitrary code execution inside the Chrome renderer's sandbox, typically chained with a separate sandbox escape for full host compromise. Anyone running Google Chrome prior to 90.0.4430.85, or Chromium as packaged by Debian and Fedora, is affected. Exploitation is confirmed in the wild: Google shipped the fix in April 2021 after active attacks, a public PoC exists (crbug.com/1195777), the bug was observed in exploit-kit attack chains, EPSS assigns an 84% probability of near-term exploitation, and CISA added it to the KEV catalog on 2021-11-03.

Do: Update Google Chrome to 90.0.4430.85 or later immediately; Debian and Fedora users should apply the chromium package updates issued by their vendors, per CISA KEV required actions. There is no strong workaround short of disabling JavaScript or restricting browsing to trusted sites. Treat this as urgent, since the flaw was already used in real attacks and exploit-kit chains, where it was typically paired with a sandbox escape for full system compromise.

8.884% KEV PoC
  • google chrome prior to 90.0.4430.85 (fixed in 90.0.4430.85)
  • debian linux (chromium package) Chromium builds prior to upstream fix 90.0.4430.85; fixed package versions not specified in source data
  • fedoraproject fedora (chromium package) Chromium builds prior to upstream fix 90.0.4430.85; fixed package versions not specified in source data
masson the order of billions of users (Chrome's global install base exceeds 1 billion desktops; Chromium additionally ships in Debian and Fedora)
Full article202 words · extracted from cyberscoop.com · click to collapse

Google's jumping on the latest zero-day.

Google Chrome Sundar Pichai
Google and Alphabet CEO Sundar Pichai speaks at Google's annual developer conference. (KIMIHIRO HOSHINO/AFP via Getty Images)

Google released an updated version of the Chrome browser on Tuesday that included seven security fixes, including a patch for a zero-day flaw that hackers may have actively been exploiting, Google said.

Google has been dealing with several serious flaws in recent days. The update details four other vulnerabilities and fixes Google had to roll out this week. Google previously fixed another zero-day flaw on April 12, as well.

If the zero-day flaw, classified as CVE-2021-21224, was exploited in concert with another vulnerability, hackers would have been able to execute arbitrary code on victims’ systems.

VerSprite Inc’s Jose Martinez reported the vulnerability, which Google describes as a Type Confusion in V8, several days ago, linking it to a proof-of-concept exploit that took advantage of the bug. That proof-of-concept code was available on Twitter, and thus accessible to the public, though there were no reports of attackers leveraging the bug in the wild.

“Google is aware of reports that exploits for CVE-2021-21224 exist in the wild,” the blog states.

The update includes solutions for Windows, Mac and Linux users.

Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/google-chrome-update-zero-day-hackers/