Tag: chrome browser

Chrome Targeted by Active In-the-Wild Exploit Tied to Undisclosed High-Severity Flaw
News

Chrome Targeted by Active In-the-Wild Exploit Tied to Undisclosed High-Severity Flaw

Google released security patches for its Chrome browser on Wednesday to fix three security holes, one of which it said had been being exploited in the wild. The high-severity vulnerability is being monitored with the Chromium issue tracker ID "466192044." In contrast to past disclosures, Google has chosen to withhold details regarding the nature of the defect, the impacted component, and the CVE identifier. The problem is found in Google's open-source Almost Native Graphics Layer Engine (ANGLE) library, according to a GitHub commit matching the Chromium bug ID. The commit note reads, "Metal: Don't use pixelsDepthPitch to size buffers." GL_UNPACK_IMAGE_HEIGHT, which may be less than the picture height, is the basis for pixelsDepthPitch. This suggests that the issue is probably a b...
Google Warns of CVE-2024-7965 Chrome Security Flaw Under Active Exploitation
News

Google Warns of CVE-2024-7965 Chrome Security Flaw Under Active Exploitation

Google has disclosed that a security vulnerability addressed in the Chrome browser's security update that was released last week is being actively exploited in the wild. The vulnerability, identified as CVE-2024-7965, is characterized as an improper implementation error in the WebAssembly and JavaScript engines of version 8. A summary of the bug in the NIST National Vulnerability Database (NVD) states that improper implementation in V8 in Google Chrome versions earlier than 128.0.6613.84 allows a remote attacker to possibly exploit heap corruption via a forged HTML page. It has been reported that a security researcher going by the online alias TheDog found and reported the vulnerability read more about Google Warns of CVE-2024-7965 Chrome Security Flaw Under Active Exploitation. ...
Google to Block Entrust Certificates in Chrome Starting November 2024
News

Google to Block Entrust Certificates in Chrome Starting November 2024

Citing compliance failures and the certificate authority's slow response to security vulnerabilities, Google has announced that it will begin blocking websites that use Entrust certificates starting on or around November 1, 2024, in its Chrome browser. Google's Chrome security team stated that over the past few years, publicly available incident reports have shown a pattern of unsettling actions by Entrust that do not live up to the expectations mentioned above. This has damaged public trust in Entrust's ability, dependability, and integrity as a publicly trusted [certificate authority] owner. In light of this, the massive tech company announced that it will default to not trust TLS server authentication certificates from Entrust beginning read more about Google to Block Entrust Cer...
Zero-Day Alert Update Chrome Now to Fix New Actively Exploited Vulnerability
News

Zero-Day Alert Update Chrome Now to Fix New Actively Exploited Vulnerability

Updates for Google's Chrome browser, which addresses four security flaws including an active zero-day vulnerability, were made available on Tuesday. Threat actors may be able to use the problem, which is tracked as CVE-2024-0519, to cause a crash by taking advantage of an out-of-bounds memory access in the V8 JavaScript and WebAssembly engine. According to MITRE's Common Weakness Enumeration (CWE), an attacker may be able to obtain secret values, such as memory addresses, by reading out-of-bounds memory. These values can then be used to get around security measures like ASLR and increase the likelihood of successfully exploiting a different danger to achieve code execution read more Zero-Day Alert Update Chrome Now to Fix New Actively Exploited Vulnerability. Get up to date o...