ZeroHour
Help Net Securitypublished ()ingested @zeljkazorz1

Google fixes Chrome zero-day with in-the-wild exploit (CVE-2024-4671)

criticalExploit / PoC exploited in the wildimportance 60CVE-2024-4671CVE-2024-4761

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2024-4671
Use-After-Free Sandbox Escape in Google Chrome/Chromium

CVE-2024-4671 is a use-after-free (CWE-416) in the Visuals component of Google Chrome and Chromium, fixed in Chrome 124.0.6367.201. It is triggered via a crafted HTML page, but the attacker must already have compromised the browser's renderer process, so this flaw is typically chained with a renderer exploit rather than used standalone. Successful exploitation enables a sandbox escape, letting the attacker break out of Chrome's renderer sandbox and gain broader access to the system beyond the browser tab. All users of Google Chrome versions prior to 124.0.6367.201 are affected, and per CISA's CPE data, Fedora's packaged Chromium builds are also in scope. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2024-05-13, indicating active exploitation in the wild; no public proof-of-concept is known, EPSS estimates an 8.3% chance of exploitation within 30 days (95th percentile), and ransomware association is unknown.

Do: Update Google Chrome to 124.0.6367.201 or later (verify via chrome://settings/help, since Chrome auto-updates may lag), and update Fedora's chromium package to the fixed build; CISA KEV requires federal agencies to apply the vendor fix on the mandated timeline. Because this sandbox escape must be chained with a renderer compromise, defenders should treat any unpatched Chrome deployment as exposed and confirm via EDR logs whether suspicious renderer-process activity occurred; enterprise admins should push the update through managed-browser channels immediately.

9.68% KEV
  • google chrome prior to 124.0.6367.201
  • fedoraproject fedora packaged Chromium builds prior to the 124.0.6367.201 fix
mass≈3+ billion Chrome/Chromium users worldwide (Chrome holds roughly 65% of desktop browser market share, with additional exposure via Chromium packaged in Fedora)
CVE-2024-4761
Actively Exploited Out-of-Bounds Write in Google Chrome V8 Engine (CVE-2024-4761)

CVE-2024-4761 is an out-of-bounds write (CWE-787) in the V8 JavaScript engine used by Google Chrome and Chromium. A remote attacker triggers the flaw by persuading a user to load a crafted HTML page, causing V8 to write beyond allocated memory bounds. Successful exploitation yields a high-impact memory corruption condition that can compromise confidentiality, integrity, and availability, potentially enabling arbitrary code execution within the browser process. All Google Chrome releases prior to 124.0.6367.207 are affected, as are Chromium-based distributions such as Fedora's Chromium package. CISA added the vulnerability to its Known Exploited Vulnerabilities catalog on 2024-05-16, confirming it is being exploited in the wild, and Google patched it in Chrome 124.0.6367.207.

Do: Update Google Chrome to 124.0.6367.207 or later on all platforms and verify the running version at chrome://settings/help; Fedora administrators should install the patched chromium package from the Fedora repositories as soon as available. Because the flaw is confirmed exploited in the wild and listed in CISA KEV, treat patching as urgent, prioritizing workstations and servers with browsers used to access untrusted web content. As an interim mitigation, restrict high-risk users' web browsing or isolate browsers until updates are applied.

8.811% KEV
  • google chrome Google Chrome prior to 124.0.6367.207
  • google chromium (V8 engine) Chromium V8 as shipped in Chrome/Chromium prior to 124.0.6367.207
  • fedoraproject fedora (Chromium package) Fedora Chromium builds containing the affected V8 (fixed version not specified in source data)
massbillions of Chrome installations potentially affected (Chrome holds roughly 65% of global browser share)
Full article340 words · extracted from helpnetsecurity.com · click to collapse

Google has fixed a Chrome zero-day vulnerability (CVE-2024-4671), an exploit for which exists in the wild.

CVE-2024-4671

About CVE-2024-4671

CVE-2024-4671 is a use after free vulnerability in the Visuals component that can be exploited by remote attackers to trigger an exploitable heap corruption via a specially crafted HTML page.

“Successful exploitation of this vulnerability could allow for arbitrary code execution in the context of the logged on user. Depending on the privileges associated with the user an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights,” CIS explains.

“Users whose accounts are configured to have fewer user rights on the system could be less impacted than those who operate with administrative user rights.”

The zero-day has been reported by an anonymous bug hunter and, according to Google, there’s an in-the-wild exploit for it. Though the company doesn’t explicitly say that the exploit is being used by attackers, chances are good that it is – or very soon will be.

The fixes

The vulnerability has been fixed in the stable desktop versions of Google Chrome:

  • v124.0.6367.201/.202 for Mac and Windows
  • v124.0.6367.201 for Linux

“The Extended Stable channel has been updated to 124.0.6367.201 for Mac and Windows which will roll out over the coming days/weeks,” the company added.

Users who have switched off automatic updating are advised to check for and implement the provided update, then restart the browser. Users who have automatic updating turned on and haven’t restarted the browser in a while should soon see a pop-up icon indicating a pending update.

UPDATE (May 14, 2024, 07:15 a.m. ET):

Google has patched another zero-day (CVE-2024-4761) likely exploited in the wild. It is an out of bounds write vulnerability in Chrome’s V8 JavaScript and WebAssembly engine.

Users of Chromium-based browsers such as Microsoft Edge, Brave, and Opera should expect fixes for that vulnerability soon. Vivaldi already has a fix.

Subscribe to our breaking news e-mail alert to never miss out on the latest breaches, vulnerabilities and cybersecurity threats. Subscribe here!

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2024/05/10/cve-2024-4671/