ZeroHour
Help Net Securitypublished ()ingested @zeljkazorz

New Chrome zero-day actively exploited, patch quickly! (CVE-2024-7971)

criticalExploit / PoC exploited in the wildimportance 60CVE-2024-7971CVE-2024-7965

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2024-7971
+1 in the same advisory: …7965
Type Confusion in Google Chromium V8 Enables Heap Corruption via Malicious Pages

Google Chromium's V8 JavaScript engine contains a type confusion flaw (CWE-843) that lets a remote attacker trigger heap corruption through a specially crafted HTML page. The attack is triggered simply by a user loading an attacker-controlled web page, with no other interaction required. Successful exploitation of heap corruption in a browser JavaScript engine typically gives the attacker code execution within the browser process, a common first step toward broader system compromise. All users of Chromium-based browsers are affected, including Google Chrome, Microsoft Edge, Opera, and any other product embedding Chromium V8. CISA added the vulnerability to the Known Exploited Vulnerabilities catalog on 2024-08-26, confirming active in-the-wild exploitation, and EPSS assigns a 20.7% probability of exploitation within 30 days (97th percentile).

Do: Update all Chromium-based browsers (Chrome, Edge, Opera, Brave) to the vendors' patched releases immediately and verify the installed version via chrome://version or edge://version. Per CISA's KEV required action, apply vendor mitigations or discontinue use if patches are unavailable; until patching completes, treat web browsing on high-value systems with caution and watch for vendors to publish the specific fixed version numbers.

9.6
group max
21% KEV PoC
  • Google Chromium V8 JavaScript engine
  • Google Chrome (Chromium-based) All versions built on the affected V8 engine prior to vendor updates (not specified in source data)
  • Microsoft Edge (Chromium-based) All versions built on the affected V8 engine prior to vendor updates (not specified in source data)
  • +1 more
massbillions of users/installations (Chrome alone is estimated at ~3 billion+ users, plus Edge, Opera, Brave and other Chromium browsers)
Full article542 words · extracted from helpnetsecurity.com · click to collapse

A new Chrome zero-day vulnerability (CVE-2024-7971) exploited by attackers in the wild has been fixed by Google.

CVE-2024-7971

About CVE-2024-7971

CVE-2024-7971 is a high-severity vulnerability caused by a type confusion weakness in V8, the open-source JavaScript and WebAssembly engine developed by Google for the Chromium and Google Chrome web browsers.

“In languages without memory safety, such as C and C++, type confusion can lead to out-of-bounds memory access,” Mitre explains the problem. (V8 is written in C++.)

As per usual, Google did not provide access to bug details and links – it’s holding off until most users are updated with a fix. The vulnerability’s NVD entry says that the flaw “allowed a remote attacker to exploit heap corruption via a crafted HTML page.”

The vulnerability has been reported by Microsoft Threat Intelligence Center (MSTIC) and Microsoft Security Response Center (MSRC), presumably after discovering the attacks.

Fixing CVE-2024-7971

Google has fixed CVE-2024-7971 and delivered 37 additional security fixes in Chrome v128.0.6613.84/.85 (for Windows and Mac) and v128.0.6613.84 (Linux).

Users are advised to upgrade their Chrome installation if they don’t have the automatic updating option switched on.

Fixes for security holes in V8 are usually propagated to Microsoft’s Edge browser quickly, as the browser uses the Blink and V8 engines developed by the Chromium team. “We are actively working on releasing a security fix,” the company stated on Wednesday.

Other Chromium-based browsers – e.g., Brave, Opera, and Vivaldi – should implement the fixes soon.

Looking for 0-days in V8

CVE-2024-7971 is the ninth actively exploited Chrome zero-day – and the third type confusion bug in the V8 engine – fixed this year.

In late 2023, Google has called on bug hunters to probe its V8 engine for zero-day flaws and report them, as well as exploit writers to try and exploit n-day and 0-day vulnerabilities. Rewards for both zero-days and exploits have been offered.

Unfortunately, attackers are looking for zero-days, as well.

UPDATE (August 27, 2024, 07:15 a.m. ET):

As confirmed by Google on Monday, among the fixes in these updates is one for CVE-2024-7965, an inappropriate implementation in V8 that has also been exploited in the wild as a zero-day. (In the wild exploitation of CVE-2024-7965 was reported after the release of the updates.)

UPDATE (August 31, 2024, 02:10 a.m. ET):

“On August 19, 2024, Microsoft identified a North Korean threat actor exploiting a zero-day vulnerability in Chromium, now identified as CVE-2024-7971, to gain remote code execution (RCE). We assess with high confidence that the observed exploitation of CVE-2024-7971 can be attributed to a North Korean threat actor targeting the cryptocurrency sector for financial gain,” Microsoft researchers say.

“Our ongoing analysis and observed infrastructure lead us to attribute this activity with medium confidence to Citrine Sleet. We note that while the FudModule rootkit deployed has also been attributed to Diamond Sleet, another North Korean threat actor, Microsoft previously identified shared infrastructure and tools between Diamond Sleet and Citrine Sleet, and our analysis indicates this might be shared use of the FudModule malware between these threat actors.”

UPDATE (September 19, 2024, 07:35 a.m. ET):

A PoC exploit for CVE-2024-7971 has been published.

Subscribe to our breaking news e-mail alert to never miss out on the latest breaches, vulnerabilities and cybersecurity threats. Subscribe here!

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2024/08/22/cve-2024-7971/