[ad_1]
By being exposed on the Internet, a browser is constantly vulnerable to attacks and flaws that are discovered. Those who develop and maintain them try to keep these defects hidden and corrected to ensure their safety.
Chrome is not immune to these flaws and 2 new ones have now been revealed by Google itself and its Project Zero. They are classified as critical and users are asked to update their browser immediately, on all platforms.
New security holes in Chrome
Chrome's security problems aren't unusual, nor are they rare. Google tries to keep your browser free from security holes, but this is not always possible. Obviously, the research giant is ready to react and that's a good thing.
Two of these situations are now reported and are in a highly critical state. From what has been described, if exploited, they can lead the attacker to take complete control of the victim's machine, with all the problems that this entails.
Some people noticed that CVE-2020-16010 was not included in the link above. This is because Chrome has separate release notes for desktop and Android. Release notes for CVE-2020-16010 (sandbox escape for Chrome on Android) are now available here: https://t.co/6hBKMuCAaK
- Ben Hawkes (@benhawkes) November 3, 2020
Various problems in the Google browser
One of the flaws is found in the desktop and Android version and thus affects Windows, macOS, Linux and the mobile version. Apparently it's in V8, this browser's javascript engine. It is usually contained in a sandbox, but with the failure it manages to escape and gain access to the operating system.
The problem is greater because it is known that code already circulating on the Internet capable of exploiting this flaw. Google has already tried to fix the problem and other glitches and therefore released a new update to Chrome. This will have the version number 86.0.4240.183 and is now available.
Security has been strengthened on Android
The second flaw only concerns Android and allows you to exploit a flaw in the browser interface. There is also a new version here, 86.0.4240.185, which is already accessible on the Play Store and should take a few days to install automatically.
From what we've seen in the past few weeks they were fertile having problems with the Google browser. The company reacted quickly and directly, but launched the necessary fixes for the different versions of Chrome.
[ad_2]
Source link