Зарегистрируйтесь сейчас для лучшей персонализированной цитаты!

Google Chrome: Apply new security update now to fix these six 'high severity' bugs

9 ноября 2022 г Hi-network.com
Image: Getty Images/iStockphoto

Google has released a security update for its Google Chrome browser on Windows, Mac and Linux to fix 10 security vulnerabilities, some of which could allow remote attackers to crash vulnerable systems. 

Google has detailed some of the fixes in a Google Chrome release update -although the company is currently withholding full details about many of the issues until most users have applied the updates, which are due to roll out over the coming days and weeks. 

Security

  • 8 habits of highly secure remote workers
  • How to find and remove spyware from your phone
  • The best VPN services: How do the top 5 compare?
  • How to find out if you are involved in a data breach -- and what to do next

In total, the latest Google Chrome update includes 10 security updates, which are also available for Google Chrome on mobile devices unless otherwise indicated. Six of the updates have been classified as 'high severity'. That means the updates should be applied as soon as possible. 

Also: Google's hackers: Inside the cybersecurity red team that keeps Google safe

The vulnerabilities could potentially enable a remote attacker to exploit 'heap corruption' via a crafted HTML page. The corruption affects the 'heap', an area of pre-reserved computer memory that a program uses to store a variable amount of data.

Heap corruption occurs when a program damages the view of the heap, which can result in a memory fault to the extent it could cause a crash. 

CVE-2022-3885 is a vulnerability in V8, the open-source JavaScript engine developed by the Chromium Project for Google Chrome and Chromium web browsers that could cause heat corruption, while CVE-2022-3886 is a vulnerability in Speech Recognition in Google Chrome that can be exploited for the same effect. 

CVE-2022-3887 is a vulnerability in Web Workers, which is used in Google Chrome to run scripts in the background without interfering with the user interface. CVE-2022-3888 is a vulnerability in WebCodecs in Google Chrome, which is used to provide low-level access to media encoders and decoders.  

Meanwhile, CVE-2022-3889 is a type confusion vulnerability in V8, providing the program with the wrong code. Each of these vulnerabilities can allow attackers to exploit heat corruption vulnerabilities. 

The last of the vulnerabilities to have been listed publicly Is CVE-2022-3890, a heap buffer overflow in Crashpad in Google Chrome on Android, which could allow a remote attacker to perform a sandbox escape, potentially enabling them to escalate privileges across an entire host environment. 

"We would also like to thank all security researchers that worked with us during the development cycle to prevent security bugs from ever reaching the stable channel," said Google, which paid bug bounty rewards of between$7,000 and$21,000 to the researchers who discovered them.

It's recommended that users apply the Google Chrome security patch for 107.0.5304.110 for Mac and Linux and 107.0.5304.106/.107 for Windows when it becomes available to protect systems from potential attacks. 

MORE ON CYBERSECURITY

  • Google Chrome zero-day flaw: Users urged to install update 'immediately'
  • CISA warning: Hackers are exploiting these 36 "significant" cybersecurity vulnerabilities - so patch now
  • Microsoft Patch Tuesday fixes 11 critical security vulnerabilities and six zero-days being actively exploited
  • These cybersecurity vulnerabilities are most popular with hackers right now - have you patched them?
  • There's been a big rise in hackers targeting Google Chrome - doing this one thing can help protect you

tag-icon Горячие метки: Технологии и оборудование Безопасность и охрана

Copyright © 2014-2024 Hi-Network.com | HAILIAN TECHNOLOGY CO., LIMITED | All Rights Reserved.