logo

Google fixes Chrome zero-days exploited at Pwn2Own 2024

ID: 93865866-752e-5c8e-9314-b49e3eaa9622

STIX ID: report--93865866-752e-5c8e-9314-b49e3eaa9622

Feed Name: Bleeping Computer

Threat Score
55/100

Date Published: 2024-03-27

Date Updated: 2026-04-20

Author: Sergiu Gatlan

...
...

Google fixed two high-severity zero-day vulnerabilities in Chrome (CVE-2024-2887 — a WebAssembly type confusion — and CVE-2024-2886 — a WebCodecs use-after-free) that were demonstrated and exploited during Pwn2Own Vancouver 2024, enabling remote code execution via crafted HTML pages; patches were released in Chrome 123.0.6312.86/.87 across platforms. The report also notes Mozilla patched two Firefox zero-days shown at the contest and references a separate actively exploited Chrome zero-day patched in January.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.