• News/
  • https://www.bleepingcomputer.com/news/security/google-fixes-first-actively-exploited-chrome-zero-day-of-2024/

Google fixes first actively exploited Chrome zero-day of 2024

BleepingComputer
·
Sergiu Gatlan
·
Published Jan 16, 2024
·
Updated

Google has released security updates to fix the first Chrome zero-day vulnerability exploited in the wild since the start of the year. "Google is aware of reports that an exploit for CVE-2024-0519 exists in the wild," the company said in a security advisory published Tuesday. The company fixed the zero-day for users in the Stable Desktop channel, with patched versions rolling out worldwide to Windows (120.0.6099.224/225), Mac (120.0.6099.234), and Linux (120.0.6099.224) users less than a week after being reported to Google. Although Google says the security update could take days or weeks to reach all impacted users, it was available immediately when BleepingComputer checked for updates today. Those who prefer not to update their web browser manually can rely on Chrome to automatically check for new updates and install them after the next launch.

​The high-severity zero-day vulnerability (CVE-2024-0519) is due to a high-severity out-of-bounds memory access weakness in the Chrome V8 JavaScript engine, which attackers can exploit to gain access to data beyond the memory buffer, providing them access to sensitive information or triggering a crash. "The expected sentinel might not be located in the out-of-bounds memory, causing excessive data to be read, leading to a segmentation fault or a buffer overflow," MITRE explains. "The product may modify an index or perform pointer arithmetic that references a memory location that is outside of the boundaries of the buffer. A subseque...

Read full article

Affected Software

3 affected components
Google Chrome=120.0.6099.224
Google Chrome=120.0.6099.225
Google Chrome=120.0.6099.234

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses the release of security updates by Google to fix the first actively exploited Chrome zero-day vulnerability of 2024.

2

What specific vulnerability is addressed in the article?

The article addresses the Chrome zero-day vulnerability identified as CVE-2024-0519.

3

What indications are there that this vulnerability is being exploited?

Google stated that they are aware of reports indicating that an exploit for CVE-2024-0519 exists in the wild.

4

When was the security advisory published regarding this vulnerability?

The security advisory was published on January 16, 2024.

5

Which software is affected by this zero-day vulnerability?

The affected software is Google Chrome.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203