Cyber Security News

Chrome Flaw Let Attacker Corrupt Memory via Crafted HTML Page

Google has updated the Stable channels to 121.0.6167.85 for Mac and Linux and 121.0.6167.85/.86 for Windows as part of a security update for Chrome.

There are 17 security fixes in this update. The upgrade will be rolled out over the coming few days and weeks.

High-Severity Flaws Addressed

A high-severity issue was identified as CVE-2024-0807, Use after free in WebAudio. This allowed a remote attacker to possibly exploit heap corruption via a crafted HTML page. 

Google awarded a $11000 bounty after Huang Xilin of Ant Group Light-Year Security Lab reported it.

The vulnerability identified as Inappropriate implementation in accessibility (CVE-2024-0812) was determined to have a high severity. 

This allowed a remote attacker to potentially exploit object corruption via a crafted HTML page. Google announced a $9000 reward and stated the reporter was anonymous.

CVE-2024-0808, Integer underflow in WebUI, was found to be a high-severity issue. This enabled a remote attacker to potentially exploit heap corruption via a malicious file. A $6000 bounty was issued by Google, as reported by Lyra Rebane (rebane2001).

Medium and Low-Severity Flaws Addressed

The Medium-severity bugs addressed in this update are listed below:

CVE-2024-0810 – Insufficient policy enforcement in DevTools, CVE-2024-0814 – Incorrect security UI in Payments, CVE-2024-0813 – Use after free in Reading Mode.

CVE-2024-0806 – Use after free in Passwords, CVE-2024-0805 – Inappropriate implementation in Downloads, and CVE-2024-0804 – Insufficient policy enforcement in iOS Security UI.

The Low- severity bugs addressed in this update are listed below:

CVE-2024-0811 – Inappropriate implementation in Extensions API and CVE-2024-0809 – Inappropriate implementation in Autofill.

Chrome Security Update

  • Mac and Linux (121.0.6167.85)
  • Windows (121.0.6167.85/.86)

Google recommended users update to the most recent patched version of Chrome as soon as possible to lessen security risks.

Update Now!

To update the Chrome web browser, you have to follow a few simple steps that we have mentioned below:-  

  • Go to the Settings option.
  • Then select About Chrome.
  • Now, you must wait, as Chrome will automatically fetch and download the latest update.
  • Then, wait for the latest version to be installed.
  • Once the installation process is complete, you will have to restart Chrome.
  • That’s it. Now you are done.
Guru Baran

Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.

Recent Posts

Hackers Target AI Infrastructure With RCE, Prompt Injection and API Key Theft

Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…

3 hours ago

Hackers Make Phishing Pages Change Their Code Every Time Someone Opens Them

Hackers are making some phishing pages harder to track by changing the code delivered to…

3 hours ago

Iran-Linked Hackers Reportedly Knock UK Power Plant Offline for Four Days

A cyber incident reportedly forced a British power plant to halt operations for about four…

4 hours ago

Russian Hackers Use New HOOKEDGE Malware to Spy on European Defense and Diplomatic Targets

Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…

4 hours ago

Ransomware Gang Claims AI Can Analyze 700GB of Stolen Data Every Hour

TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…

5 hours ago

Hackers Compromise Hundreds of WordPress Sites to Deploy Amatera Stealer via ClickFix

A fake student resume is being used to place a remote-access tool on researchers’ Windows…

6 hours ago