Chrome Targeted by Active In-the-Wild Exploit Tied to Undisclosed High-Severity Flaw
Google released security patches for its Chrome browser on Wednesday to fix three security holes, one of which it said had been being exploited in the wild.
The high-severity vulnerability is being monitored with the Chromium issue tracker ID "466192044." In contrast to past disclosures, Google has chosen to withhold details regarding the nature of the defect, the impacted component, and the CVE identifier.
The problem is found in Google's open-source Almost Native Graphics Layer Engine (ANGLE) library, according to a GitHub commit matching the Chromium bug ID. The commit note reads, "Metal: Don't use pixelsDepthPitch to size buffers." GL_UNPACK_IMAGE_HEIGHT, which may be less than the picture height, is the basis for pixelsDepthPitch.
This suggests that the issue is probably a b...



