Install Latest Chrome Update to Patch 0
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2020-6407 | Out of bounds memory access in streams in Google Chrome prior to 80.0.3987.122 allowed a remote attacker to potentially exploit heap corruption via a crafted HT Out of bounds memory access in streams in Google Chrome prior to 80.0.3987.122 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. NVD description · AI analysis pending | 8.8 | 2% |
| — | ||
| CVE-2020-6418 | Type Confusion in Google Chrome's V8 Engine Enables Heap Corruption CVE-2020-6418 is a type confusion vulnerability (CWE-843) in V8, the JavaScript engine used in Google Chrome and Chromium, affecting versions prior to 80.0.3987.122. A remote attacker triggers it by persuading a user to open a crafted HTML page whose JavaScript causes V8 to mishandle object types (public PoCs reference a JSCreate side-effect issue), potentially leading to heap corruption. Successful exploitation can yield arbitrary code execution in the browser, a common stepping stone for further compromise on the victim's system. Any Chrome/Chromium deployment with the vulnerable V8 was affected, including Chromium packages shipped by Fedora, Red Hat Enterprise Linux, and Debian. The flaw was a zero-day exploited in the wild when patched in February 2020; it is listed in CISA KEV (added 2021-11-03) and carries a very high EPSS of 78.8%, making it a priority patch. Do: Update Google Chrome to 80.0.3987.122 or later and confirm the running version via chrome://settings/help or chrome://version. Apply the updated Chromium packages from Fedora, Red Hat, and Debian on managed Linux endpoints and check whether any hosts still run pre-fix Chromium. Given the KEV listing and 78.8% EPSS, treat patching as urgent; as an interim mitigation on unpatched systems, limit untrusted web browsing or restrict JavaScript from untrusted sites. | 8.8 | 79% | KEV PoC ×2 |
| massbillions of users/installations (Chrome's global install base runs to billions, and at disclosure in February 2020 every Chrome user on a pre-80.0.3987.122… |
Full article331 words · extracted from thehackernews.com · click to collapse
Ravie LakshmananFeb 25, 2020
Google yesterday released a new critical software update for its Chrome web browser for desktops that will be rolled out to Windows, Mac, and Linux users over the next few days.
The latest Chrome 80.0.3987.122 includes security fixes for three new vulnerabilities, all of which have been marked 'HIGH' in severity, including one that (CVE-2020-6418) has been reportedly exploited in the wild.
The brief description of the Chrome bugs, which impose a significant risk to your systems if left unpatched, are as follows:
- Integer overflow in ICU — Reported by André Bargull on 2020-01-22
- Out of bounds memory access in streams (CVE-2020-6407) — Reported by Sergei Glazunov of Google Project Zero on 2020-01-27
- Type confusion in V8 (CVE-2020-6418) — Reported by Clement Lecigne of Google's Threat Analysis Group on 2020-02-18
The Integer Overflow vulnerability was disclosed by André Bargull privately to Google last month, earning him $5,000 in rewards, while the other two vulnerabilities — CVE-2020-6407 and CVE-2020-6418 — were identified by experts from the Google security team.
Google has said CVE-2020-6418, which stems from a type confusion error in its V8 JavaScript rendering engine, is being actively exploited, although technical information about the vulnerability is restricted at this time.
The search giant has not disclosed further details of the vulnerabilities so that it gives affected users enough time to install the Chrome update and prevent hackers from exploiting them.
A successful exploitation of the integer overflow or out-of-bounds write flaws could allow a remote attacker to compromise a vulnerable system by tricking the user into visiting a specially crafted web page that takes advantage of the exploit to execute arbitrary code on the target system.
It's recommended that Windows, Linux, and macOS users download and install the latest version of Chrome by heading to Help > "About Chrome" from the settings menu.
Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.
Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2020/02/google-chrome-zero-day.html