Google Patches Major Zero-Day Vulnerability in Chrome

The Chrome exploit is used in attacks that leverage a waterhole-style injection in a Korean-language news portal.

Advertisement
By Indo-Asian News Service | Updated: 5 November 2019 18:00 IST

A new exploited vulnerability in Google Chrome web browser called "CVE-2019-13720", which is a zero-day vulnerability, has been spotted by Russian cyber-security firm Kaspersky. The firm has reported it Google and a patch has been released. Zero-day vulnerabilities are essentially previously unknown software bugs that can be exploited by attackers to inflict serious and unexpected damage. The detected exploit was used in what the cyber-security firm calls 'Operation WizardOpium'.

Certain similarities in the code point to a possible link between this campaign and Lazarus attacks.

"The finding of a new Google Chrome zero-day in the wild once again demonstrates that it is only collaboration between the security community and software developers, as well as constant investment in exploit prevention technologies, that can keep us safe from sudden and hidden strikes by threat actors," Anton Ivanov, Security Expert at Kaspersky, said in a statement.

Advertisement

The new exploit is used in attacks that leverage a waterhole-style injection in a Korean-language news portal. A malicious JavaScript code is inserted in the main page, which in turn, loads a profiling script from a remote site to further check if the victim's system could be infected by examining versions of the browser's user credentials.

Advertisement

The vulnerability tries to exploit the bug through the Google Chrome browser and the script checks if version 65 or later is being used.

The exploit gives an attacker a Use-After-Free (UaF) condition, which is very dangerous because it can lead to code execution scenarios.

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Further reading: Google Chrome, Kaspersky
Advertisement

Related Stories

Popular Mobile Brands
  1. Realme 16 Pro+ 5G Retail Box Reveals Price in India Weeks Before Launch
  2. De De Pyaar De 2 OTT Release: Know Everything About This Ajay Devgan Starrer Romance Comed
  3. OnePlus Nord 6 Visits Certification Website, Could Launch Soon
  4. Realme Pad 3 5G to Launch Alongside the Realme 16 Pro Series
  5. iPhone Fold Seen in Leaked Renders With Pixel-Fold Like Design
  6. Why Apple Might Pay a 230 Percent Premium for iPhone 17 Pro RAM in 2026
  7. Oppo K15 Turbo Pro Tipped to Launch With This MediaTek Chip
  8. Samsung Galaxy Book 6 Ultra, Galaxy Book 6 Pro Listed on Bluetooth SIG
  9. Xiaomi 17 Ultra Leica Edition Will Launch in China With These Features
  10. Red Magic 11 Air Launch Confirmed; Could Feature This Snapdragon Chip
  1. Vritta OTT Release Date Revealed: Know When and Where to Watch it Online
  2. Rajini Gaang OTT Release Date: Know When and Where to Watch it Online
  3. De De Pyaar De 2 OTT Release Update: Know Everything About Streaming, Plot, Cast, and More
  4. Baahubali: The Epic Now Available for Streaming Online: Everything You Need to Know
  5. Global Warming May Overshoot and Trigger the Next Ice Age, Say Scientists
  6. Weapons OTT Release Date: When and Where to Watch it Online?
  7. Paradise (2024) Now Streaming Online: What You Need to Know
  8. Red Magic 11 Air Launch Confirmed; Tipster Hints at Presence of Snapdragon 8 Elite Chip
  9. Samsung Reportedly Plans to Expand India Manufacturing With Focus on Phone Displays, May Source Chips From India
  10. Realme 16 Pro+ 5G Price in India Leaked as Tipster Reveals Retail Box Ahead of Launch on January 6
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.