Google has rolled out a critical security update for Chrome, addressing an actively exploited zero-day vulnerability—the seventh such flaw patched in the browser this year. The update, detailed by BleepingComputer on September 12, fixes a total of 230 security issues.
The most severe of these is tracked as CVE-2024-8904. This high-severity heap buffer overflow vulnerability resides in Chrome's V8 JavaScript engine and carries a CVSS score of 8.8. If successfully exploited, it could allow a remote attacker to execute arbitrary code on a victim's machine simply by directing them to a malicious webpage.
The fact that this marks the seventh zero-day exploited in the wild since the start of 2024 underscores the persistent value of browsers as targets for advanced adversaries. This pattern highlights an ongoing cat-and-mouse game where defenders must constantly guard against flaws discovered and weaponized before vendors can release patches.
True to its standard protocol, Google has delayed disclosing specific details about the in-the-wild exploits. This practice is intended to limit the window for copycat attacks, as the company prioritizes ensuring a broad user base has updated before providing a technical blueprint that could be misused.
System administrators and security teams are urged to deploy the update without delay. The patch advances Chrome to version 128.0.6613.178 for Windows and Mac, and 128.0.6613.178 or .179 for Linux. This event serves as another stark reminder that rigorous and automated patch management is a foundational defense against emerging web-based threats.
Google 為 Chrome 推出關鍵安全更新,修補一個正被積極利用的零日漏洞——這是該瀏覽器今年內第七個被修補的同類漏洞。據 BleepingComputer 於 9 月 12 日詳述,本次更新共修復了 230 個安全問題。
其中最嚴重者編號為 CVE-2024-8904。這個高嚴重性的堆疊緩衝區溢出漏洞存在於 Chrome 的 V8 JavaScript 引擎中,CVSS 評分為 8.8。若被成功利用,遠端攻擊者只需引導受害者訪問惡意網頁,即可在其機器上執行任意代碼。
此事件標誌著自 2024 年初以來第七個在野外被利用的零日漏洞,突顯了瀏覽器作為高級持續性威脅目標的持續價值。此模式反映了一場持續的攻防博弈:防禦方必須不斷防範那些在供應商發布補丁前已被發現並武器化的漏洞。
Google 遵循標準協議,暫緩披露具體的野外利用細節。此舉旨在限制模仿攻擊的窗口期,優先確保廣泛用戶基礎完成更新,以免提供可能被濫用的技術藍圖。
系統管理員和安全團隊被敦促立即部署更新。此補丁將 Chrome 版本推進至 128.0.6613.178(Windows 和 Mac 版),Linux 版本則為 128.0.6613.178 或 .179。此事件再次鮮明提醒:嚴格且自動化的補丁管理是對抗新興網絡威脅的基礎防禦手段。
