News: 1612537624

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Chrome zero-day bug that is actively being abused by bad folks affects Edge, Vivaldi, and other Chromium-tinged browsers

(2021/02/05)


If you use Google Chrome or a Chromium-based browser such as Microsoft Edge, update it immediately and/or check it for updates over the coming days: there is a zero-day bug being "actively exploited" in the older version of Chrome that will also affect other vendors' browsers.

Details are intentionally scant until enough of the wider world has installed the update, but the flaw exists in how Chrome handles heap overflows in V8, Chromium's Javascript engine.

[1]

"Google is aware of reports that an exploit for CVE-2021-21148 [the zero-day; more details below] exists in the wild," [2]said the loquacious adtech firm in a statement.

The V8 vuln affects Chromium-based browsers in general and not just Google Chrome itself. Tarquin Wilton-Jones, developer at Vivaldi, told The Register : "This is a generic Chromium issue, and affects Chromium-based browsers. We released an update for our desktop stable channel yesterday, which includes the Chromium update for this issue. We are currently testing our Android build with the update, and hope to have it released soon."

[3]

Vivaldi composes sweet ad-blocking symphony for users of browser's Android version [4]READ MORE

This means users of Microsoft Edge, Brave, and other fringe browsers need to get updating pronto. Firefox users may enjoy a moment – but only a moment – of smugness.

While Google's [5]blog post announcing the new update was terse and undescriptive, it revealed that the zero-day is known as CVE-2021-21148 (details will appear at [6]this link at a later date) and was reported by software architect Mattias Buelens on 24 January. The flaw itself, described only as "heap buffer overflow", exists in V8, Chromium's open-source Javascript and WebAssembly engine.

Two days later, Google's Threat Analysis Group [7]warned the world that North Koreans were probing zero-day researchers, though there is no evidence so far to suggest a firm link between the two.

OmahaProxy, a site that tracks what's running under the hood in Chrome, [8]shows that between the previous stable build (88.0.4324.146) and the latest (ending 150) V8's version number was incremented, from 8.8.278.14 to .15 in the newest Chrome version.

Rubbish software security patches responsible for a quarter of zero-days last year [9]READ MORE

The [10]Chromium log for the latest version (88.0.4324.150), naturally, contains no specific details of [11]the bug yet. Chromium's automatic vuln disclosure terms are for details to be published 14 weeks after a fix, if the bug isn't revealed sooner.

[12]

Back in early November, Google patched [13]another Chrome-affecting bug in V8 that allowed a remote attacker to exploit heap corruption through a specially crafted HTML page. Details of that bug haven't yet entered the public domain but should do so pretty soon, if Google abides by its own 14-week disclosure rules. ®

Get our [14]Tech Resources



[1] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YB15pYDVhgfzQODnzhsh3QAAAIk&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[2] https://chromereleases.googleblog.com/2021/02/stable-channel-update-for-desktop_4.html

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YB15pYDVhgfzQODnzhsh3QAAAIk&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[4] https://www.theregister.com/2020/08/13/vivaldi_android_3_2_ad_block/

[5] https://chromereleases.googleblog.com/2021/02/stable-channel-update-for-desktop_4.html

[6] https://cve.mitre.org/cgi-bin/cvename.cgi?name=2021-21148

[7] https://www.theregister.com/2021/01/26/norks_hack_researchers/

[8] https://omahaproxy.appspot.com/

[9] https://www.theregister.com/2021/02/03/enigma_patch_zero/

[10] https://chromium.googlesource.com/chromium/src/+log/88.0.4324.146..88.0.4324.150?pretty=fuller&n=10000

[11] https://bugs.chromium.org/p/chromium/issues/detail?id=1170176

[12] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YB15pYDVhgfzQODnzhsh3QAAAIk&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[13] https://www.theregister.com/2020/11/04/google_chrome_critical_updates/

[14] https://whitepapers.theregister.com/

Cross reference (very)

Greybearded old scrote

I think [1]somebody was bleating about Open Source security failures recently.

[1] https://www.theregister.com/2021/02/04/google_open_source_security/

AnAnonymousCanuck

Chrome and Chromium are bugs, web bugs reporting everything to Google..

YMMV (actually it's Google so it won't)

AAC

Atchoo!

nematoad

"The V8 vuln affects Chromium-based browsers in general and not just Google Chrome itself. "

Ah the joys of a monoculture! Didn't we go through this once before with IE?

Looks like Chrome caught a cold and everyone sneezes.

Re: Atchoo!

Dan 55

Well, everybody except Firefox.

Re: Atchoo!

mark l 2

There are more than 2 browser engines. So its not just Firefox users that can benefit from not being based on the Chromium based browser.

The biggest none Chromium based browser is Safari which comes as the default browser on every Apple device so has millions of active users.

I use Linux though so its not available on that platform, but I could install Konqueror and set it to use webkit engine

Chrome is the new Flash

TaabuTheCat

That is all.

It is no wonder that people are so horrible when they start life as children.
-- Kingsley Amis