Security Experts:

Chrome 95 Update Patches Exploited Zero-Days, Flaws Disclosed at Tianfu Cup

A Chrome 95 update released by Google on Thursday patches two actively exploited Chrome vulnerabilities, as well as flaws that were disclosed recently at a Chinese hacking contest.

The actively exploited vulnerabilities are tracked as CVE-2021-38000, which has been described as an insufficient validation of untrusted input in Intents, and CVE-2021-38003, an inappropriate implementation issue affecting the V8 JavaScript engine. CVE-2021-38000 was discovered in September and CVE-2021-38003 was identified just three days ago.

Google employees have been credited for both zero-day vulnerabilities. No information has been made available regarding the attacks in which these vulnerabilities have been exploited.

More than a dozen Chrome vulnerabilities discovered this year have been exploited in the wild, according to data from Google’s Project Zero group.

The latest Chrome 95 update includes eight security fixes, including at least seven classified as high severity. Wei Yuan of MoyunSec VLab earned $10,000 for a use-after-free bug, and while that is the highest bounty awarded by Google, two of the CVEs patched this week earned two research teams a total of $300,000 at the Tianfu Cup hacking contest that took place recently in China.

The Kunlun Lab and 360 Alpha Lab teams each earned $150,000 for Chrome exploit chains that achieved remote code execution with a sandbox escape. The rewards were paid out by the organizers of Tianfu Cup — Google does not pay out separate rewards for vulnerabilities disclosed at hacking competitions such as Tianfu Cup and Pwn2Own.

SecurityWeek has learned that the Kunlun Lab exploit also involved a Windows kernel bug that has yet to be patched.

At the Tianfu Cup, participants earned a total of $1.9 million for demonstrating exploits targeting Windows 10, Ubuntu, iOS 15 on iPhone 13 Pro, Microsoft Exchange, Chrome, Safari, Adobe Reader, Parallels Desktop, QEMU, Docker, VMware ESXi and Workstation, and ASUS routers.

Related: Google Patches Two More Exploited Zero-Day Vulnerabilities in Chrome

Related: Chrome 94 Update Patches Actively Exploited Zero-Day Vulnerability

Related: Google Warns of Exploited Zero-Days in Chrome Browser

view counter
Eduard Kovacs (@EduardKovacs) is a contributing editor at SecurityWeek. He worked as a high school IT teacher for two years before starting a career in journalism as Softpedia’s security news reporter. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.