Billons of Chrome users at risk from hacker attacks — severe flaw exploited

Padlock shadow in front of the Google Chrome logo
(Image credit: Ink Drop/Shutterstock)

Google is in the process of rolling out patches that address a high-severity security flaw in its Chrome browser. According to Google, this flaw has come under active exploitation in the wild.

The flaw (tracked as CVE-2024-7971) is a confusion bug in the V8 JavaScript and WebAssembly engine (h/t to The Hacker News). Google acknowledged the flaw in a blog post saying that the company is "aware that an exploit for CVE-2024-7971 exists in the wild."

According to the National Vulnerability Database, this confusion bug "allowed a remote attacker to exploit heap corruption via a crafted HTML page." For those unaware, heap corruption refers to memory exploits. In some cases they can be benign according to BlackBerry, however, they can also cause a fatal memory fault where the system won't allow associated processes to occur.

In Google's blog, they credit the Microsoft Threat Intelligence Center and the Microsoft Security Response Center for discovering and reporting the flaw on August 19. 

As the time of writing, Google has not released any details about the nature of any attacks exploiting the flaw or who might have been weaponizing it. According to Hacker News, this is third type confusion page that has been patched this year by Google.

To apply Google's fix, you'll need to upgrade to Chrome version 128.0.6613.84/.85 for Windows and macOS. Linux users will need to update to version 128.0.6613.84. Again, the fix is being rolled out gradually so it might not immediately be available to all Chrome users. Make sure to check back frequently if you don't see the new version just yet.

Other Chromium-based browsers may also be affected including Brave, Microsoft Edge, Opera and Vivaldi and users should apply any fixes as soon as they become available. 

More from Tom's Guide

TOPICS
Scott Younker
West Coast Reporter

Scott Younker is the West Coast Reporter at Tom’s Guide. He covers all the lastest tech news. He’s been involved in tech since 2011 at various outlets and is on an ongoing hunt to build the easiest to use home media system. When not writing about the latest devices, you are more than welcome to discuss board games or disc golf with him. 

Read more
Android 12
Google March Android Security Update fixes two high severity vulnerabilities — update now
Google Pixel 9 held in the hand.
Google just fixed a zero-day kernel flaw used by hackers and 47 other vulnerabilities — update your Android phone right now
and image of the Google Chrome logo on a laptop
Billions of Chrome users at risk from new browser-hijacking Syncjacking attack — how to stay safe
and image of the Google Chrome logo on a laptop
Over 600,000 Chrome users at risk after 16 browser extensions compromised by hackers — what you need to know
and image of the Google Chrome logo on a laptop
Popular Chrome extensions hijacked by hackers in widespread cyberattack — 3.2 million at risk
An email icon open on a laptop screen
New Google Calendar notification attack could be hiding in your inbox — here's how to protect yourself
Latest in Online Security
Green skull on smartphone screen.
Over one million Android devices infected with password-stealing, pre-installed botnet malware — how to stay safe
Android 12
Google March Android Security Update fixes two high severity vulnerabilities — update now
An Android bot next to an Android TV remote
Millions of Android TVs hijacked in massive botnet — how to see if yours is at risk
Poster of Elon Musk saying "I am stealing from you"
Elon Musk's DOGE blocked from accessing your data – and 3 in 4 Americans agree
A fake text message on a smartphone being held by both hands.
Toll road scams are worse than ever — what to look for and how to stay safe
A phone with Google Search open on screen
Google just made it easier to remove your personal info from search results — here's how to do it
Latest in News
NYTimes Connections
NYT Connections today hints and answers — Thursday, March 6 (#634)
Galaxy Z Fold 6 shown in hand
Samsung just killed the crease with this breakthrough foldable phone display
Sam Altman
ChatGPT-4.5 delayed in surprise announcement — and it could launch with a controversial new payment model
Green skull on smartphone screen.
Over one million Android devices infected with password-stealing, pre-installed botnet malware — how to stay safe
Switch 2 console and logo
Nintendo Switch 2 — analyst just tipped release window
Apple tvOS 18 new features
New tvOS 18 code hints at Apple's much rumored smart home hub