HomeCyber BalkansGoogle Releases Patch for Actively Exploited Zero-Day Vulnerability

Google Releases Patch for Actively Exploited Zero-Day Vulnerability

Published on

spot_img


Zero-Day Vulnerability

Google on Wednesday rolled out fixes to address a new actively exploited zero-day in the Chrome browser.

Tracked as CVE-2023-5217, the high-severity vulnerability has been described as a heap-based buffer overflow in the VP8 compression format in libvpx, a free software video codec library from Google and the Alliance for Open Media (AOMedia).

Exploitation of such buffer overflow flaws can result in program crashes or execution of arbitrary code, impacting its availability and integrity.

Clément Lecigne of Google’s Threat Analysis Group (TAG) has been credited with discovering and reporting the flaw on September 25, 2023, with fellow researcher Maddie Stone noting on X (formerly Twitter) that it has been abused by a commercial spyware vendor to target high-risk individuals.

No additional details have been disclosed by the tech giant other than to acknowledge that it’s “aware that an exploit for CVE-2023-5217 exists in the wild.”

The latest discovery brings to five the number of zero-day vulnerabilities to Google Chrome for which patches have been released this year –

  • CVE-2023-2033 (CVSS score: 8.8) – Type confusion in V8
  • CVE-2023-2136 (CVSS score: 9.6) – Integer overflow in Skia
  • CVE-2023-3079 (CVSS score: 8.8) – Type confusion in V8
  • CVE-2023-4863 (CVSS score: 8.8) – Heap buffer overflow in WebP

The development comes as Google assigned a new CVE identifier, CVE-2023-5129, to the critical flaw in the libwebp image library – originally tracked as CVE-2023-4863 – that has come under active exploitation in the wild, considering its broad attack surface.

Users are recommended to upgrade to Chrome version 117.0.5938.132 for Windows, macOS, and Linux to mitigate potential threats. Users of Chromium-based browsers such as Microsoft Edge, Brave, Opera, and Vivaldi are also advised to apply the fixes as and when they become available.

-REFERENCE: https://thehackernews.com/2023/09/update-chrome-now-google-releases-patch.html

-K.Z





Source link

Latest articles

AWS Bedrock AgentCore Vulnerability Enabled AI Agent Hijacking with a Single Prompt

Newly Disclosed Vulnerability in Amazon Bedrock AgentCore Raises Concerns About Credential Theft The cybersecurity landscape...

Oracle Health breach impacts nearly 20 million people

Oracle Health Faces Major Data Breach: 20 Million Affected In a significant revelation, Oracle Health...

Hackers Utilize AI Agents and GodPotato Exploit to Achieve Windows SYSTEM Privileges

In a troubling development reported by cybersecurity researchers, a group of hackers successfully exploited...

Citrix NetScaler Critical RCE Vulnerability CVE-2026-107406

Urgent Security Advisory Issued by Citrix for Critical Vulnerability in NetScaler Products In a recent...

More like this

AWS Bedrock AgentCore Vulnerability Enabled AI Agent Hijacking with a Single Prompt

Newly Disclosed Vulnerability in Amazon Bedrock AgentCore Raises Concerns About Credential Theft The cybersecurity landscape...

Oracle Health breach impacts nearly 20 million people

Oracle Health Faces Major Data Breach: 20 Million Affected In a significant revelation, Oracle Health...

Hackers Utilize AI Agents and GodPotato Exploit to Achieve Windows SYSTEM Privileges

In a troubling development reported by cybersecurity researchers, a group of hackers successfully exploited...