Site icon TheCyberThrone

Google Patched Eighth Zeroday in Chrome – CVE-2024-5274

Advertisements

Google has released a security patch to address a new Zeroday vulnerability in Chrome browser, marking the fixed Zeroday count to eight in this year alone.

The vulnerability tracked as CVE-2024-5274 is a type confusion’ in the V8 JavaScript engine, the Google researcher Clément Lecigne, and Brendon Tiszka discovered it. The company confirmed that the flaw is exploited in attacks in the wild.

A “type confusion” vulnerability occurs when a program incorrectly handles variables of one type as if they were another type. This can happen due to flaws in type checking, casting, or other operations involving variable types, leading to unpredictable behavior and potential security risks.

Advertisements

Google did not publish details about the attacks exploiting the vulnerability. Access to bug details and links may be kept restricted until a majority of users are updated with a fix.

Google addressed the issue with the release of version 125.0.6422.112/.113 for Windows and Mac, while Linux users will get the update on version 125.0.6422.112 in the coming weeks.

The vulnerability CVE-2024-5274 is the third actively exploited zero-day disclosed this month, after CVE-2024-4671 and CVE-2024-4947.

Exit mobile version