会员登录 - 用户注册 - 设为首页 - 加入收藏 - 网站地图 Google revealed a security flaw on Halloween, so maybe update Chrome now!

Google revealed a security flaw on Halloween, so maybe update Chrome now

时间:2024-09-22 01:46:21 来源:摩登家庭人人影视网 作者:产品中心 阅读:856次

While you were out trick or treating on Halloween night, Google engineers released a warning about a new Chrome security flaw.

On Oct. 31, Google shared informationregarding two recently discovered vulnerabilities. The search giant has confirmed that a zero-day exploit exists for one of these security issues.

A zero-day exploit is basically when a nefarious party discovers a bug they can use for a cyber attack before the original developer can issue a fix.

Google released a security update to fix the problem that will roll out automatically to all users in the coming days and weeks. Users can manually update Google Chrome immediately by going to the “About Google Chrome” section in the menu bar.

“This version addresses vulnerabilities that an attacker could exploit to take control of an affected system,” said a statementreleased by the U.S. Department of Homeland Security Cybersecurity and Infrastructure Security Agency (CISA).

Mashable Light SpeedWant more out-of-this world tech, space and science stories?Sign up for Mashable's weekly Light Speed newsletter.By signing up you agree to our Terms of Use and Privacy Policy.Thanks for signing up!

Google hasn’t divulged many details about the flaws, which the company says is for security purposes.

“Access to bug details and links may be kept restricted until a majority of users are updated with a fix,” reads the security alert from Google. “We will also retain restrictions if the bug exists in a third party library that other projects similarly depend on, but haven’t yet fixed.”

However, here’s what we know so far. The two vulnerabilities, CVE-2019-13720 and CVE-2019-13721, are considered “use-after-free” flaws. This is when an application attempts to reference previously used memory after it’s been freed or deleted. When this occurs, bad actors can exploit the memory corruption to execute malicious code.

One of the two Chrome bugs affect the PDFium library, which generates PDFs. The other, which has a zero-day exploit in the wild, involves Chrome’s audio component.

The discoverywas made by Anton Ivanov and Alexey Kulaev, two researchers from the cybersecurity firm Kaspersky.

Google Chrome’s last major security vulnerability involving a zero-day exploit occurred just earlier this year. The company pushed out an update in March after a memory management error involving FileReader was discovered.

(责任编辑:关于我们)

相关内容
  • Keurig K Mini deal — get $30 off at Target
  • 五色土现身名山中峰乡
  • 部分电影节开幕式演出嘉宾已经到雅
  • 遭遇强降雨 全市公路相继告急
  • NASA says Earth just had the hottest day ever recorded
  • 确保强农惠农专项清理检查工作见实效
  • 突出“四个重点”推动联系帮扶村科学发展
  • 带领乡亲订报读报,发展产业富民兴村
推荐内容
  • “新丰味”喜获中国首届县域品牌擂台赛十大营销创新品牌
  • 新规出台 网购弊端能否“药到病除”?
  • 50天 查处3000多起违法停车行为
  • 华南农业大学赴河源紫金县开展 “双百行动”,解决“卡脖子”问题
  • South Korean lawmakers brace for US election as Harris, Trump diverge on North Korea
  • 抓教研 促科研保质量