• News/
  • https://www.bleepingcomputer.com/news/security/google-fixes-chrome-zero-days-exploited-at-pwn2own-2024/

Google fixes Chrome zero-days exploited at Pwn2Own 2024

BleepingComputer
·
Sergiu Gatlan
·
Published Mar 27, 2024
·
Updated

Google fixed seven security vulnerabilities in the Chrome web browser on Tuesday, including two zero-days exploited during the Pwn2Own Vancouver 2024 hacking competition. The first (tracked as CVE-2024-2887) is a high-severity type confusion weakness in the WebAssembly (Wasm) open standard. Manfred Paul demoed this vulnerability on the first day of Pwn2Own as part of a double-tap remote code execution (RCE) exploit using a crafted HTML page and targeting both Chrome and Edge. The second zero-day is tracked as CVE-2024-2886 and was exploited by KAIST Hacking Lab's Seunghyun Lee during the second day of the CanSecWest Pwn2Own contest. Described as a use-after-free (UAF) weakness in the WebCodecs API used by web apps to encode and decode audio and video content, it allows remote attackers to perform arbitrary reads/writes via crafted HTML pages. Lee also used CVE-2024-2886 to gain remote code execution using a single exploit targeting both Google Chrome and Microsoft Edge. Google fixed the two zero-days in the Google Chrome stable channel, version 123.0.6312.86/.87 for Windows and Mac and 123.0.6312.86 for Linux users, which will roll out worldwide over the coming days.

Mozilla also fixed two Firefox zero-days exploited by Manfred Paul at Pwn2Own Vancouver 2024 on the same day the bugs were demoed. While it only took Mozille one day and Google five days to patch these vulnerabilities, vendors usually take their time to release patches for security flaws demoed at Pwn2Own since...

Read full article

Affected Software

3 affected components
Google Chrome=123.0.6312.86
Google Chrome=123.0.6312.87
Mozilla Firefox
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What vulnerabilities were addressed in the recent Google Chrome update?

Seven security vulnerabilities were fixed, including two zero-days exploited at Pwn2Own 2024.

2

What is the significance of the zero-day vulnerabilities mentioned?

Zero-day vulnerabilities are critical security flaws that are actively exploited by attackers before a fix is available.

3

What specific zero-day vulnerability was highlighted in the article?

The article mentions a high-severity type confusion vulnerability tracked as CVE-2024-2887.

4

Did the security update affect any other browsers besides Google Chrome?

Yes, Mozilla Firefox was also identified in the context of the vulnerabilities discussed.

5

When were the fixes for the vulnerabilities released?

The fixes were released on March 27, 2024.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203