Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Cybercrime

Chrome 95 Update Patches Exploited Zero-Days, Flaws Disclosed at Tianfu Cup

A Chrome 95 update released by Google on Thursday patches two actively exploited Chrome vulnerabilities, as well as flaws that were disclosed recently at a Chinese hacking contest.

A Chrome 95 update released by Google on Thursday patches two actively exploited Chrome vulnerabilities, as well as flaws that were disclosed recently at a Chinese hacking contest.

The actively exploited vulnerabilities are tracked as CVE-2021-38000, which has been described as an insufficient validation of untrusted input in Intents, and CVE-2021-38003, an inappropriate implementation issue affecting the V8 JavaScript engine. CVE-2021-38000 was discovered in September and CVE-2021-38003 was identified just three days ago.

Google employees have been credited for both zero-day vulnerabilities. No information has been made available regarding the attacks in which these vulnerabilities have been exploited.

More than a dozen Chrome vulnerabilities discovered this year have been exploited in the wild, according to data from Google’s Project Zero group.

The latest Chrome 95 update includes eight security fixes, including at least seven classified as high severity. Wei Yuan of MoyunSec VLab earned $10,000 for a use-after-free bug, and while that is the highest bounty awarded by Google, two of the CVEs patched this week earned two research teams a total of $300,000 at the Tianfu Cup hacking contest that took place recently in China.

The Kunlun Lab and 360 Alpha Lab teams each earned $150,000 for Chrome exploit chains that achieved remote code execution with a sandbox escape. The rewards were paid out by the organizers of Tianfu Cup — Google does not pay out separate rewards for vulnerabilities disclosed at hacking competitions such as Tianfu Cup and Pwn2Own.

Advertisement. Scroll to continue reading.

SecurityWeek has learned that the Kunlun Lab exploit also involved a Windows kernel bug that has yet to be patched.

At the Tianfu Cup, participants earned a total of $1.9 million for demonstrating exploits targeting Windows 10, Ubuntu, iOS 15 on iPhone 13 Pro, Microsoft Exchange, Chrome, Safari, Adobe Reader, Parallels Desktop, QEMU, Docker, VMware ESXi and Workstation, and ASUS routers.

Related: Google Patches Two More Exploited Zero-Day Vulnerabilities in Chrome

Related: Chrome 94 Update Patches Actively Exploited Zero-Day Vulnerability

Related: Google Warns of Exploited Zero-Days in Chrome Browser

Written By

Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Click to comment

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Learn how to address potential risks and not restrict AI adoption in your organization. See what a centralized AI gateway is and how it works in practice.

Register

Join as we decipher the world of zero trust and share war stories on securing an organization by eliminating implicit trust and continuously validating every stage of a digital interaction.

Register

People on the Move

Sherman Chu joined The Port Authority of New York & New Jersey as CISO.

Doppel has named Joey Rachid as Chief Security Advisor and Field Chief Information Security Officer.

Delinea has appointed Timothy Regan as Chief Financial Officer.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.