Security Experts:

Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Cybercrime

Chrome 95 Update Patches Exploited Zero-Days, Flaws Disclosed at Tianfu Cup

A Chrome 95 update released by Google on Thursday patches two actively exploited Chrome vulnerabilities, as well as flaws that were disclosed recently at a Chinese hacking contest.

A Chrome 95 update released by Google on Thursday patches two actively exploited Chrome vulnerabilities, as well as flaws that were disclosed recently at a Chinese hacking contest.

The actively exploited vulnerabilities are tracked as CVE-2021-38000, which has been described as an insufficient validation of untrusted input in Intents, and CVE-2021-38003, an inappropriate implementation issue affecting the V8 JavaScript engine. CVE-2021-38000 was discovered in September and CVE-2021-38003 was identified just three days ago.

Google employees have been credited for both zero-day vulnerabilities. No information has been made available regarding the attacks in which these vulnerabilities have been exploited.

More than a dozen Chrome vulnerabilities discovered this year have been exploited in the wild, according to data from Google’s Project Zero group.

The latest Chrome 95 update includes eight security fixes, including at least seven classified as high severity. Wei Yuan of MoyunSec VLab earned $10,000 for a use-after-free bug, and while that is the highest bounty awarded by Google, two of the CVEs patched this week earned two research teams a total of $300,000 at the Tianfu Cup hacking contest that took place recently in China.

The Kunlun Lab and 360 Alpha Lab teams each earned $150,000 for Chrome exploit chains that achieved remote code execution with a sandbox escape. The rewards were paid out by the organizers of Tianfu Cup — Google does not pay out separate rewards for vulnerabilities disclosed at hacking competitions such as Tianfu Cup and Pwn2Own.

SecurityWeek has learned that the Kunlun Lab exploit also involved a Windows kernel bug that has yet to be patched.

At the Tianfu Cup, participants earned a total of $1.9 million for demonstrating exploits targeting Windows 10, Ubuntu, iOS 15 on iPhone 13 Pro, Microsoft Exchange, Chrome, Safari, Adobe Reader, Parallels Desktop, QEMU, Docker, VMware ESXi and Workstation, and ASUS routers.

Related: Google Patches Two More Exploited Zero-Day Vulnerabilities in Chrome

Related: Chrome 94 Update Patches Actively Exploited Zero-Day Vulnerability

Related: Google Warns of Exploited Zero-Days in Chrome Browser

Written By

Eduard Kovacs (@EduardKovacs) is a contributing editor at SecurityWeek. He worked as a high school IT teacher for two years before starting a career in journalism as Softpedia’s security news reporter. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Click to comment

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Expert Insights

Related Content

Cybercrime

Zendesk is informing customers about a data breach that started with an SMS phishing campaign targeting the company’s employees.

Cybercrime

The release of OpenAI’s ChatGPT in late 2022 has demonstrated the potential of AI for both good and bad.

Cybercrime

The FBI dismantled the network of the prolific Hive ransomware gang and seized infrastructure in Los Angeles that was used for the operation.

Cloud Security

VMware vRealize Log Insight vulnerability allows an unauthenticated attacker to take full control of a target system.

IoT Security

Lexmark warns of a remote code execution (RCE) vulnerability impacting over 120 printer models, for which PoC code has been published.

Cybercrime

A new study by McAfee and the Center for Strategic and International Studies (CSIS) named a staggering figure as the true annual cost of...

Mobile & Wireless

Apple rolled out iOS 16.3 and macOS Ventura 13.2 to cover serious security vulnerabilities.

Email Security

Microsoft is urging customers to install the latest Exchange Server updates and harden their environments to prevent malicious attacks.