Google fixes ninth Chrome zero-day tagged as exploited this year

Share:

​​Today, Google released a new Chrome emergency security update to patch a zero-day vulnerability tagged as exploited in attacks.

“Google is aware that an exploit for CVE-2024-7971 exists in the wild,” the company said in an advisory published on Wednesday.

This high-severity zero-day vulnerability is caused by a type confusion weakness in Chrome’s V8 JavaScript engine. Security researchers with the Microsoft Threat Intelligence Center (MSTIC) and Microsoft Security Response Center (MSRC) reported it on Monday.

Although such security flaws can commonly enable attackers to trigger browser crashes after data allocated into memory is interpreted as a different type, they can also exploit them for arbitrary code execution on targeted devices running unpatched browsers.

Google has fixed the zero-day with the release of 128.0.6613.84/.85 for Windows/macOS and 128.0.6613.84 (Linux), versions that will roll out to all users in the Stable Desktop channel over the coming weeks.

While Chrome updates automatically when security patches are available, users can also speed up the process by going to the Chrome menu > Help > About Google Chrome, letting the update finish, and clicking the ‘Relaunch’ button to install it.

Today’s update was immediately available when BleepingComputer looked for new updates today.

​Even though Google confirmed the CVE-2024-7971 vulnerability was used in attacks, the company has yet to share additional information regarding in-the-wild exploitation.

“Access to bug details and links may be kept restricted until a majority of users are updated with a fix,” Google said.

“We will also retain restrictions if the bug exists in a third party library that other projects similarly depend on, but haven’t yet fixed.”

CVE-2024-7971 is the ninth Chrome zero-day patched by Google in 2024, either exploited in the wild or at the Pwn2Own hacking contest:

  • CVE-2024-0519: A high-severity out-of-bounds memory access weakness within the Chrome V8 JavaScript engine, allowing remote attackers to exploit heap corruption via a specially crafted HTML page, leading to unauthorized access to sensitive information.
  • CVE-2024-2887: A high-severity type confusion flaw in the WebAssembly (Wasm) standard. It could lead to remote code execution (RCE) exploits leveraging a crafted HTML page.
  • CVE-2024-2886: A use-after-free vulnerability in the WebCodecs API used by web applications to encode and decode audio and video. Remote attackers exploited it to perform arbitrary reads and writes via crafted HTML pages, leading to remote code execution.
  • CVE-2024-3159: A high-severity vulnerability caused by an out-of-bounds read in the Chrome V8 JavaScript engine. Remote attackers exploited this flaw using specially crafted HTML pages to access data beyond the allocated memory buffer, resulting in heap corruption that could be leveraged to extract sensitive information.
  • CVE-2024-4671: A high-severity use-after-free flaw in the Visuals component that handles the rendering and displaying of content in the browser.
  • CVE-2024-4761: An out-of-bounds write problem in Chrome’s V8 JavaScript engine, which is responsible for executing JS code in the application.
  • CVE-2024-4947: Type confusion weakness in the Chrome V8 JavaScript engine enabling arbitrary code execution on the target device.
  • CVE-2024-5274: A type confusion Chrome’s V8 JavaScript engine that can lead to crashes, data corruption, or arbitrary code execution

Leave a Comment

Your email address will not be published. Required fields are marked *

loader-image
London, GB
1:24 am, Jul 2, 2025
weather icon 21°C
L: 20° | H: 22°
scattered clouds
Humidity: 76 %
Pressure: 1014 mb
Wind: 7 mph NNE
Wind Gust: 0 mph
UV Index: 0
Precipitation: 0 mm
Clouds: 33%
Rain Chance: 0%
Visibility: 10 km
Sunrise: 4:48 am
Sunset: 9:20 pm
DailyHourly
Daily ForecastHourly Forecast
Today 10:00 pm
weather icon
20° | 22°°C 0.38 mm 38% 11 mph 79 % 1022 mb 0 mm/h
Tomorrow 10:00 pm
weather icon
14° | 26°°C 0 mm 0% 13 mph 55 % 1028 mb 0 mm/h
Fri Jul 04 10:00 pm
weather icon
15° | 26°°C 0 mm 0% 12 mph 57 % 1028 mb 0 mm/h
Sat Jul 05 10:00 pm
weather icon
15° | 25°°C 1 mm 100% 15 mph 89 % 1022 mb 0 mm/h
Sun Jul 06 10:00 pm
weather icon
14° | 19°°C 1 mm 100% 13 mph 81 % 1012 mb 0 mm/h
Today 4:00 am
weather icon
18° | 20°°C 0 mm 0% 6 mph 77 % 1015 mb 0 mm/h
Today 7:00 am
weather icon
18° | 19°°C 0.2 mm 20% 5 mph 79 % 1016 mb 0 mm/h
Today 10:00 am
weather icon
21° | 21°°C 0.2 mm 20% 6 mph 71 % 1017 mb 0 mm/h
Today 1:00 pm
weather icon
19° | 19°°C 0.38 mm 38% 4 mph 69 % 1018 mb 0 mm/h
Today 4:00 pm
weather icon
23° | 23°°C 0.35 mm 35% 6 mph 41 % 1019 mb 0 mm/h
Today 7:00 pm
weather icon
23° | 23°°C 0.01 mm 1% 11 mph 28 % 1020 mb 0 mm/h
Today 10:00 pm
weather icon
18° | 18°°C 0 mm 0% 10 mph 34 % 1022 mb 0 mm/h
Tomorrow 1:00 am
weather icon
16° | 16°°C 0 mm 0% 7 mph 37 % 1025 mb 0 mm/h
Name Price24H (%)
Bitcoin(BTC)
€89,528.73
-1.47%
Ethereum(ETH)
€2,038.28
-3.41%
Tether(USDT)
€0.85
-0.01%
XRP(XRP)
€1.84
-3.19%
Solana(SOL)
€124.46
-5.10%
USDC(USDC)
€0.85
-0.01%
Dogecoin(DOGE)
€0.133778
-4.52%
Shiba Inu(SHIB)
€0.000009
-2.25%
Pepe(PEPE)
€0.000008
-4.97%
Scroll to Top