• News/
  • https://www.bleepingcomputer.com/news/security/google-fixes-one-more-chrome-zero-day-exploited-at-pwn2own/

Google fixes one more Chrome zero-day exploited at Pwn2Own

BleepingComputer
·
Sergiu Gatlan
·
Published Apr 3, 2024
·
Updated

Google has fixed another zero-day vulnerability in the Chrome browser, which was exploited by security researchers during the Pwn2Own hacking contest last month. Tracked as CVE-2024-3159, this high-severity security flaw is caused by an out-of-bounds read weakness in the Chrome V8 JavaScript engine. Remote attackers can exploit the vulnerability using crafted HTML pages to gain access to data beyond the memory buffer via heap corruption, which can provide them with sensitive information or trigger a crash. Palo Alto Networks security researchers Edouard Bochin and Tao Yan demoed the zero-day on the second day of Pwn2Own Vancouver 2024 to defeat V8 hardening. Their double-tap exploit allowed them to execute arbitrary code on Google Chrome and Microsoft Edge, earning them a $42,500 award. Google has now fixed the zero-day in the Google Chrome stable channel version 123.0.6312.105/.106/.107 (Windows and Mac) and 123.0.6312.105 (Linux), which will roll out worldwide over the coming days.

​One week ago, Google fixed two more Chrome zero-days exploited at Pwn2Own Vancouver 2024. The first, a high-severity type confusion weakness (CVE-2024-2887) in the WebAssembly (Wasm) open standard, was targeted by Manfred Paul's double-tap RCE exploit that targeted both Chrome and Edge. The second, a use-after-free (UAF) weakness in the WebCodecs API (CVE-2024-2886), was also exploited by KAIST Hacking Lab's Seunghyun Lee to gain remote code execution on both Chromium web browsers. Mozilla als...

Read full article

Affected Software

6 affected components
Google Chrome=123.0.6312.105
Google Chrome=123.0.6312.106
Google Chrome=123.0.6312.107
Microsoft Edge
Mozilla Firefox
Google Android
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses the fixing of a zero-day vulnerability in Google Chrome that was exploited during the Pwn2Own hacking contest.

2

What is the identified vulnerability in the article?

The vulnerability is tracked as CVE-2024-3159 and is classified as a high-severity security flaw.

3

Which versions of Chrome are affected by this vulnerability?

The affected versions of Chrome are 123.0.6312.105, 123.0.6312.106, and 123.0.6312.107.

4

What other browsers are mentioned in relation to this vulnerability?

The article also mentions that Microsoft Edge, Mozilla Firefox, and Google Android could be affected.

5

What was the context in which this vulnerability was exploited?

The vulnerability was exploited by security researchers during the Pwn2Own hacking contest.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203