Threat Advisory

Chrome 129 Fixes Critical V8 Security Flaw and Multiple Vulnerabilities

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Researchers have released Chrome 129 for Windows, Mac, and Linux, addressing multiple vulnerabilities that pose security risks, ranging from critical to low severity. The most notable flaw is CVE-2024-8904, a high-severity type confusion vulnerability in the V8 engine, which could lead to arbitrary code execution. Other vulnerabilities include issues in V8, Omnibox, Autofill, and UI components, with Google awarding a total of $13,000 in bug bounties. Users are encouraged to update their browsers to mitigate these security risks.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Researchers have released Chrome 129 for Windows, Mac, and Linux, addressing multiple vulnerabilities that pose security risks, ranging from critical to low severity. The most notable flaw is CVE-2024-8904, a high-severity type confusion vulnerability in the V8 engine, which could lead to arbitrary code execution. Other vulnerabilities include issues in V8, Omnibox, Autofill, and UI components, with Google awarding a total of $13,000 in bug bounties. Users are encouraged to update their browsers to mitigate these security risks.[emaillocker id="1283"]

 

  • CVE-2024-8904: Type confusion in V8 JavaScript engine, CVSS 8.8 (high severity), can allow remote code execution.
  • CVE-2024-8905: Inappropriate implementation in V8, CVSS 6.5 (medium severity).
  • CVE-2024-8906: Incorrect security UI in Downloads, CVSS 5.9 (medium severity), could mislead users during file downloads.
  • CVE-2024-8907: Insufficient data validation in Omnibox, CVSS 5.5 (medium severity), may result in unintended behavior.
  • CVE-2024-8908: Inappropriate implementation in Autofill, CVSS 4.3 (low severity), could cause improper data handling.
  • CVE-2024-8909: UI component vulnerability, CVSS 3.8 (low severity), affects Chrome’s interface.

 

These vulnerabilities, especially the high-severity flaw in V8, pose significant security risks. Users should update Chrome to ensure protection against potential exploits.

RECOMMENDATION:

  • We strongly recommend you update Google Chrome for Windows, macOS to version 129.0.6668.58/.59 and Linux to version 129.0.6668.58.

REFERENCES:

The following reports contain further technical details:

https://cybersecuritynews.com/chrome-129-released/

[/emaillocker]
crossmenu