Google Chrome Security Update – 17 January 2024

Google has released an updated Chrome version 120.0.6099.234 for Mac, 120.0.6099.224 for Linux, and version 120.0.6099.224/225 for Windows.

The addressed vulnerabilities could allow the remote attacker to execute arbitrary code and gain access to the affected system by persuading the victim to visit a specially crafted website.

Sample of the addressed vulnerabilities:

Google Chrome Code Execution Vulnerability (CVE-2024-0517):

  • CVSS: 8.8
  • Attack Vector: Network
  • Attack Complexity: Low
  • Privileges Required: None
  • User Interaction: Required
  • Consequences: Gain Access

It should be highlighted that Google is aware that a public exploit for CVE-2024- 0519 exists in the wild.

Vulnerabilities
  • CVE-2024-0517
  • CVE-2024-0518
  • CVE-2024-0519
Mitigations

The enterprise should deploy this patch as soon as the testing phase is completed.

Google Chrome Security Update

References