ZeroSecurity - Information Security News
  • Home
  • Security
    • Exploits
    • Mobile Security
  • Malware
  • Breaches
  • Crypto
  • Privacy
  • Tech
    • AI
    • Downloads
      • Malwarebytes
      • Exploits
      • Paper Downloads
    • Reviews
No Result
View All Result
SUBSCRIBE
ZeroSecurity - Information Security News
  • Home
  • Security
    • Exploits
    • Mobile Security
  • Malware
  • Breaches
  • Crypto
  • Privacy
  • Tech
    • AI
    • Downloads
      • Malwarebytes
      • Exploits
      • Paper Downloads
    • Reviews
No Result
View All Result
ZeroSecurity - Information Security News
No Result
View All Result
Home Exploits

Google Patches 4th Chrome Zero-Day (CVE-2024-5274) in Two Weeks

Kyle by Kyle
May 24, 2024
in Exploits
Reading Time: 2 mins read
Google releases urgent Chrome update to patch actively exploited high-severity zero-day vulnerability CVE-2024-5274, the 4th Chrome zero-day fixed in 2 weeks amid cybersecurity threats.
Share on FacebookShare on Twitter

Again, Google has moved swiftly to address a critical vulnerability in its widely-used Chrome web browser, releasing an urgent security update on Thursday to neutralize an actively exploited zero-day flaw. This marks the fourth vulnerability to be patched within two weeks, underscoring the ongoing battle against cyber threats targeting popular software.

You might also like

Hackers Exploit Maximum-Severity Cisco Zero-Day Bug Since 2023 (CVE-2026-20127)

DoubleClickjacking – The Stealthy New Web Exploit Threatening User Security

Critical Vulnerabilities Exposed in Ruijie Networks Cloud Platform

Exploited Vulnerability Triggers Emergency Response

The high-severity vulnerability, tracked as CVE-2024-5274, is a type confusion flaw residing within the V8 JavaScript and WebAssembly engine, a core component of the Chrome browser. Google acknowledged that an exploit for this vulnerability already exists in the wild, posing a significant risk to users.

While Google refrained from divulging specific details about the vulnerability or its active exploitation to safeguard users, the company swiftly credited Clement Lecigne of Google’s Threat Analysis Group (TAG) and Brendon Tiszka of Chrome Security for reporting the flaw. No bug bounty reward will be awarded for this discovery.

Chrome vulnerabilities, particularly zero-days, have long been a target for commercial surveillance software vendors and other malicious actors. Google’s TAG researchers have previously reported several instances of zero-days being exploited by spyware vendors, highlighting the persistent threats posed to the popular browser.

A Flurry of Patches in Recent Weeks

The patching of CVE-2024-5274 marks the fourth Chrome zero-day to be addressed within the last 15 days, following the resolution of CVE-2024-4671 (use-after-free in Visuals), CVE-2024-4761 (out-of-bounds write in V8), and CVE-2024-4947 (type confusion in V8). In total, Google has resolved eight Chrome zero-days so far this year, with three of them being demonstrated at the prestigious Pwn2Own Vancouver 2024 hacking contest in March.

Prompt Updating Recommended

The latest Chrome iteration, addressing CVE-2024-5274, is now rolling out as version 125.0.6422.112 for Linux and version 125.0.6422.112/.113 for Windows and macOS. Google has also released Chrome for Android versions 125.0.6422.112/.113 with the same security fixes. Users are strongly advised to update their Chrome browsers immediately to safeguard against potential exploitation of this critical vulnerability.

Previous Post

Ransomware Attacks Target VMware ESXi Infrastructure Following Interesting Pattern

Next Post

Exposing the Dark Web Scam: Fake Pegasus Spyware Code Sold for Millions

Kyle

Kyle

Writer, and editor at ZeroSecurity. Interested in Information Security, the Blockchain, and an overall tech enthusiast. "Formal education will make you a living; self-education will make you a fortune." Contact me here: [email protected]

Recommended For You

Photo of the CISCO logo and text saying "You have been hacked!"

Hackers Exploit Maximum-Severity Cisco Zero-Day Bug Since 2023 (CVE-2026-20127)

March 6, 2026
What is DoubleClickJacking?

DoubleClickjacking – The Stealthy New Web Exploit Threatening User Security

January 1, 2025

Critical Vulnerabilities Exposed in Ruijie Networks Cloud Platform

December 25, 2024

Vulnerability (CVE-2024-54143 ) Discovered in OpenWrt’s Firmware Upgrade System

December 13, 2024

Cybercriminals Unleash Advanced Phishing-as-a-Service Toolkit Targeting Microsoft 365 Users

November 29, 2024

Major Security Vulnerability Uncovered in qBittorrent Client

November 1, 2024

Related News

Malicious Chrome Extensions Steal AI Data and Hijack Revenue in DarkSpectre Campaign

Malicious Chrome Extensions Steal AI Data and Hijack Revenue in DarkSpectre Campaign

January 30, 2026
KPMG Netherlands Listed as Victim by Nova Ransomware Group

KPMG Netherlands Listed as Victim by Nova Ransomware Group

January 24, 2026
RansomHouse Claims Breach of Key Apple Assembler Luxshare

RansomHouse Claims Breach of Key Apple Assembler Luxshare

January 20, 2026
ZeroSecurity - Information Security News

We cover the latest in technology news, Crypto, Artificial Intelligence, and the threat trends impacting these sectors.

Categories

Piracy

Tutorials

Programming

Malware Analysis

Downloads

  • Contact us
  • Press
  • Writers
  • Privacy Policy
  • Terms of Service

© 2026 ZeroSecurity, All Rights Reserved.

No Result
View All Result
  • Home
  • Security
    • Tools
  • Exploits
  • Data Breaches
  • Malware
  • Privacy
  • Mobile Security
  • Contact Us
    • Press
  • Privacy Policy

© 2026 ZeroSecurity, All Rights Reserved.

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.