Highlights: Google discloses zero-day vulnerability in Google Chrome. The flaw could be used by attackers to gain control of a victim’s system. The vulnerability is said to be due to the involvement of a memory mismanagement bug in the FileReader web API. Google recently seeded the new version 72.0.3626.121 of Chrome and stated that the new version patches a security flaw. It did not detail the vulnerability (vuln) at the time, but did say that it’s aware of the exploit for the flaw, called CVE-2019-5786, which exists in the wild. The company has now published a blog post that reveals that the flaw was a 0-day (zero-day) vulnerability, meaning it was possibly being exploited since there was no patch available for it at the time. Some additional information is now available on the flaw, thanks to a Google Security Blog post by Clement Lecigne of Google's Threat Analysis Group. Before we delve into the details, we suggest that you immediately check and update the Chrome browser on your devices to version 72.0.3626.121. As per the blog post detailing the vuln, Google reported two zero-day vulns that were not disclosed publicly. One of them affected Google Chrome while the other one affects Microsoft Windows OS. There is no precise information on what the CVE-2019-5786 vulnerability does but Google says that it is present in “Use-after-free in FileReader.” As per the Center for Internet Security (CIS), “Successful exploitation of this vulnerability could allow an attacker to execute arbitrary code in the context of the browser. Depending on the privileges associated with this application, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.” The new vuln involves a memory mismanagement bug that is present in the FileReader web API. The flaw could not only be used to read unauthorised files but is also said to be much more harmful as it could be used for Remote Code Execution (RCE). RCE could allow an attacker to gain control, install malware and do many other things on a user’s device. To be safe from this threat, the first thing one should do is update their Google Chrome browser on all of their devices. In case there is no option to update, for some reason, one should refrain from visiting malicious websites and run software without admin rights. Switching to another browser is always an option in case none of the recommendations work for you. Related Reads: Google receives flak for not patching PNG vulnerability, researchers say millions of Android users still at risk
from Latest Technology News https://ift.tt/2XMBHIQ
flipkart
Subscribe to:
Post Comments (Atom)
flipkart
Edit videos on your mobile phone using the YouTube Create App
YouTube has introduced its new mobile app called ‘YouTube Create’. This app offers an easy way for creators to edit their videos right from ...
- September 2023 (83)
- August 2023 (126)
- July 2023 (113)
- June 2023 (102)
- May 2023 (162)
- April 2023 (160)
- March 2023 (148)
- February 2023 (136)
- January 2023 (173)
- December 2022 (163)
- November 2022 (163)
- October 2022 (181)
- September 2022 (178)
- August 2022 (174)
- July 2022 (136)
- June 2022 (125)
- May 2022 (146)
- April 2022 (130)
- March 2022 (143)
- February 2022 (132)
- January 2022 (145)
- December 2021 (157)
- November 2021 (239)
- October 2021 (269)
- September 2021 (270)
- August 2021 (212)
- July 2021 (252)
- June 2021 (225)
- May 2021 (184)
- April 2021 (181)
- March 2021 (343)
- February 2021 (299)
- January 2021 (320)
- December 2020 (334)
- November 2020 (305)
- October 2020 (318)
- September 2020 (340)
- August 2020 (347)
- July 2020 (337)
- June 2020 (310)
- May 2020 (308)
- April 2020 (418)
- March 2020 (316)
- February 2020 (282)
- January 2020 (329)
- December 2019 (323)
- November 2019 (393)
- October 2019 (403)
- September 2019 (386)
- August 2019 (454)
- July 2019 (579)
- June 2019 (509)
- May 2019 (697)
- April 2019 (725)
- March 2019 (746)
- February 2019 (702)
- January 2019 (932)
- December 2018 (758)
- November 2018 (729)
- October 2018 (835)
- September 2018 (838)
- August 2018 (548)
- March 2018 (24)
-
Huawei, it seems, cannot seem to steer away from controversy around its smartphones’ camera capabilities. This time, a Chinese photographer ...
-
Now that the first Developer Preview of the next version of Android has gone live, we can expect to see more and more reports of upcoming fe...
-
If the DL Q33 sniper rifle is not being useful enough for you in Call of Duty: Mobile, the game is offering a limited-period free upgrade to...
No comments:
Post a Comment