Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Vulnerabilities

Google Rushes to Patch Eighth Chrome Zero-Day This Year

Google warns of in-the-wild exploitation of CVE-2023-7024, a new Chrome vulnerability, the eighth documented this year.

Chrome security

Google on Wednesday announced emergency patches for a Chrome vulnerability that is under active exploitation. This is the eighth zero-day documented this year.

The issue, tracked as CVE-2023-7024, is described as a high-severity heap buffer overflow bug in Chrome’s WebRTC component.

Supported by major browser makers, WebRTC (Web Real-Time Communication) is an open source project that provides real-time communication via APIs.

“Google is aware that an exploit for CVE-2023-7024 exists in the wild,” the internet giant notes in an advisory. The security hole was reported on December 19, just one day before the patches came out.

The company has not shared technical information on the bug itself, nor has it provided details on the observed attacks exploiting it.

However, it said that the flaw was reported by Clément Lecigne and Vlad Stolyarov of Google’s Threat Analysis Group (TAG), which suggests that it might be exploited by commercial surveillance software vendors.

Advertisement. Scroll to continue reading.

Recently, Google TAG researchers uncovered several other security defects exploited by spyware vendors, including a zero-day that forced Apple (CVE-2023-41064), Google, and Mozilla (CVE-2023-4863) to release emergency patches, and a Chrome vulnerability (CVE-2023-5217) resolved at the end of September.

Aside from CVE-2023-5217 and CVE-2023-4863, Google this year resolved five other Chrome bugs exploited in the wild, namely CVE-2023-6345, CVE-2023-4762, CVE-2023-3079, CVE-2023-2033, and CVE-2023-2136, making CVE-2023-7024 the eighth documented Chrome zero-day of 2023.

The latest Chrome iteration is now rolling out as version 120.0.6099.129 for macOS and Linux, and as versions 120.0.6099.129/130 for Windows.

Google also announced that it has updated the Chrome Extended Stable channel to version 120.0.6099.129 for macOS and to version 120.0.6099.130 for Windows.

Related: Chrome 120 Update Patches High-Severity Vulnerabilities

Related: Chrome 120 Patches 10 Vulnerabilities

Related: Chrome 119 Patches 15 Vulnerabilities

Written By

Ionut Arghire is an international correspondent for SecurityWeek.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join this live webinar as we explore why exploitation is outpacing remediation, where risk is growing fastest, and what security leaders can do to close the gap before attackers take advantage.

Register

CodeSecCon bridges the gap between dev and security. Discover best practices for secure coding, innovative risk-reduction tools, and safe AI integration to cultivate a true DevSecOps culture. Safely secure your apps!

Register

People on the Move

Barry Childe has joined data sciences tech company Datavault AI as Chief Information Security Officer.

John DeSimone, the former CEO of Nightwing, has been named Chief Operating Officer at Everfox.

Sectigo has appointed Prem Hareesh as Corporate Chief Technology Officer.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.