Google just patched the fifth zero-day exploit for Chrome this year

Google has released a security update for the Chrome browser to fix a zero-day vulnerability exploit that has been used by threat actors. This is the fifth time this year the company has had to issue a patch for one of these vulnerabilities, as reported by Bleeping Computer.

"Google is aware that an exploit for CVE-2024-4671 exists in the wild," the company said in a short advisory. It did not issue any specifics as to the nature of the real-world attack or the identity of the threat actors. This is common for Google, as it likes to wait until a majority of users have updated the software before announcing specific details.

We do know some stuff about the exploit. It’s being classified as a “high-severity issue” and as a “user after free” vulnerability. These bugs arise when a program references a memory location after it has been deallocated, leading to any number of serious consequences from a crash to a random execution of code. It looks like the CVE-2024-4671 vulnerability is attached to the visuals component that handles rendering and the display of content on the browser.

The exploit was discovered and reported to Google by an anonymous researcher. The fix is available for Mac, Windows and Linux and updates will continue to roll out to users over the coming days and weeks. Chrome updates automatically with security fixes, so users can confirm they are running the latest version of the browser by going to Settings and About Chrome. Users of Chromium-based browsers like Microsoft Edge, Brave, Opera and Vivaldi should also update to a new version as soon as they are available. 

As stated, this is the fifth of this type of flaw addressed by Google this year. I don’t mean “within the last calendar year.” I mean in 2024. Three were discovered back in March at the Pwn2Own hacking contest in Vancouver. This isn’t a record or anything. Google found and fixed five in one month back in 2020.

Zero-day exploits have been a constant thorn in Google’s side. These are a type of cyberattack that take advantage of an unknown or unaddressed security flaw in computer software, hardware or firmware. The company typically pays out big money for bug discoveries, as part of its Vulnerability Rewards Program.

This article originally appeared on Engadget at https://www.engadget.com/google-just-patched-the-fifth-zero-day-exploit-for-chrome-this-year-153723334.html?src=rss https://www.engadget.com/google-just-patched-the-fifth-zero-day-exploit-for-chrome-this-year-153723334.html?src=rss
Erstellt 14d | 10.05.2024, 16:30:11


Melden Sie sich an, um einen Kommentar hinzuzufügen

Andere Beiträge in dieser Gruppe

Fortnite's new post-apocalyptic season taps into Fallout, Mad Max and X-Men

Epic Games has an uncanny habit of making sure Fortnite is in tune with the cultural

24.05.2024, 15:50:13 | Engadget
Engadget Podcast: Microsoft goes Copilot+ crazy

Microsoft is leaning even more into AI after launching a new Copilot+ AI PC initiative earlier this year. It's a new set of standards for PCs with powerful neural processing units (NPUs), and it co

24.05.2024, 13:40:09 | Engadget
The best Memorial Day sale tech deals we could find - Save big on Apple, Anker and Ooni gear

In the midst of beach trips and grilling sessions this weekend, it's worth briefly turning to the i

24.05.2024, 13:40:07 | Engadget
'Challengers' VFX artists show how they did that tennis ball POV scene

Challengers, the tennis movie starring Zendaya, Mike Faist and Josh O'Connor, is not the first movie you'd think of for

24.05.2024, 13:40:06 | Engadget
Crow Country is a darkly meditative callback to survival horror’s past

Is it blasphemous to call a survival horror game “cozy”? Maybe so, but while thinking back on my playthrough of

24.05.2024, 13:40:05 | Engadget
The Morning After: Samsung’s secret war on repair

Manufacturers may hate independent repair stores, but Samsung and Apple appeared to accept the direction the political wind was blowing in. Sadly,

24.05.2024, 11:20:14 | Engadget