Google rushes out fix for another Chrome zero
Full article501 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
It’s the third previously unknown vulnerability that Chrome has addressed this year.
Google has released an urgent software update for a flaw in the popular Chrome browser amid reports that an exploit for the bug is already available.
The vulnerability is in Blink, the feature that Chrome uses to convert HTML code to web pages, and could allow an attacker to execute code remotely or conduct a denial-of-service attack on a machine, according to IBM. An anonymous researcher reported the issue to Google on March 9, and the company released a fix for the bug on March 12.
It’s the third so-called zero-day, or previously unknown, vulnerability that Chrome has addressed this year. It’s an example of the high-stakes cat-and-mouse game between attackers searching for holes in popular software and vendors moving to plug them.
In a blog post, Google Chrome’s Prudhvikumar Bommana did not offer additional details on the bug. “Access to bug details and links may be kept restricted until a majority of users are updated with a fix,” he wrote, adding that Google was aware of reports that the vulnerability had been exploited in the wild
Vulnerabilities in popular web browsers can be particularly valuable to spies, allowing them to cast a vast surveillance net from which to pluck individual targets. Such was apparently the case when hackers used three zero-days in Internet Explorer to target people working on North Korean issues in 2019 and 2020.
It was not immediately clear which hackers were exploiting the new Blink vulnerability.
It’s been a busy few weeks for Chrome’s security team. On March 2, Chrome released a fix for another critical bug in the browser’s audio component. And just weeks earlier, Chrome issued a patch for a flaw in the browser’s JavaScript engine.
Latest Podcasts
Government
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
Feds accuse China of ‘systematic’ distillation of U.S. AI models
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
Jail time for Maine child in 764 marks turning point in federal law enforcement
Technology
Threats
Policy
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities
Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/chrome-zero-day-google-blink/