viralamo

Menu
  • Technology
  • Science
  • Money
  • Culturs
  • Trending
  • Video

Subscribe To Our Website To Receive The Last Stories

Join Us Now For Free
Home
Technology
Google fixes two more Chrome zero-days that were under active exploit
Technology

Google fixes two more Chrome zero-days that were under active exploit

03/11/2020

The word ZERO-DAY is hidden amidst a screen filled with ones and zeroes.

Google has patched two zero-day vulnerabilities in its Chrome browser, the third time in two weeks that the company has fixed a Chrome security flaw that’s under active exploit.

According to a Monday tweet from Ben Hawkes, the head of Google’s Project Zero vulnerability and exploit research arm, CVE-2020-16009, as the first vulnerability is tracked, is a remote code-execution bug in V8, Chrome’s open source JavaScript engine. A second security flaw, CVE-2020-16010, is a heap-based buffer overflow in Chrome for Android. Hawkes said it allows attackers to escape the Android sandbox, suggesting that hackers may have been using it in combination with a separate vulnerability.

Hawkes didn’t provide additional details, such as what desktop versions of Chrome were actively targeted, who the victims were, or how long the attacks had been going on. It also wasn’t clear if the same attack group was responsible for all three exploits. CVE-2020-16009 was in part discovered by a member of Google’s Threat Analysis Group, which focuses on government-backed hacking, suggesting that exploits of that vulnerability may be the work of a nation-state. Project Zero was involved in the discovery of all three of the zero-days.

Advertisement

The updates come two weeks after Google fixed CVE-2020-15999, an actively exploited vulnerability in Freetype, which Chrome and other, non-Google apps use to render fonts. To gain code-execution capabilities, hackers were combining exploits with a separate one that targeted currently unpatched bug in Windows 10 and Windows 7.

Desktop versions of Chrome typically update automatically. That means that, for most users, patches for CVE-2020-16009 and CVE-2020-15999 have already been installed, as long as they’ve recently restarted their browser. Chrome for Android is updated through Google Play. The Chrome Android advisory said the fix is incorporated into version 86.0.4240.185. The notice went on to say the update would be available “over the next few weeks,” but the phone I checked (a Pixel) already had it installed.

Source link

Share
Tweet
Pinterest
Linkedin
Stumble
Google+
Email
Prev Article
Next Article

Related Articles

Microsoft trains world’s largest Transformer language model
A preprint paper coauthored by researchers at Microsoft, the Indian …

Microsoft’s AI recommends lockdown strategies to curb coronavirus

How Riot Games is gunning for its second big esport with Valorant
Riot Games spent a decade building League of Legends into …

How Riot Games is gunning for its second big esport with Valorant

Leave a Reply Cancel reply

Find us on Facebook

Related Posts

  • Facebook collaborates with governments to develop Messenger coronavirus resources
    Facebook collaborates with governments to develop Messenger …
    23/03/2020
  • Beat Saber is now an Oculus studio after Facebook acquisition
    Publisher engagement startup Insticator bets on commenting …
    31/01/2020
  • PlayStation 5 logo revealed as PS4 surpasses 106 million systems sold
    PlayStation 5 logo revealed as PS4 surpasses …
    07/01/2020
  • Competitive mobile game maker Skillz will do a quick IPO at $3.5 billion valuation
    Competitive mobile game maker Skillz will do …
    02/09/2020
  • Court ruling paves the way for Facebook to settle its facial recognition lawsuit
    Avaaz: Facebook continues to fail at flagging …
    04/12/2020

Popular Posts

  • DDoSers are abusing Microsoft RDP to make attacks more powerful
    DDoSers are abusing Microsoft RDP to make …
    23/01/2021 0
  • The Last of Us Part II takes Game of the Year at The Game Awards
    The DeanBeat: My favorite games of 2020
    26/12/2020 0
  • How to build tech products for a diverse user base
    How to build tech products for a …
    26/12/2020 0
  • Researchers open-source state-of-the-art object tracking AI
    AI research survey finds machine learning needs …
    26/12/2020 0
  • PlayStation and Nintendo spent 2020 vying for TV game ad crown
    PlayStation and Nintendo spent 2020 vying for …
    26/12/2020 0

viralamo

Pages

  • Contact Us
  • Privacy Policy
Copyright © 2021 viralamo
Theme by MyThemeShop.com

Ad Blocker Detected

Our website is made possible by displaying online advertisements to our visitors. Please consider supporting us by disabling your ad blocker.

Refresh
We use cookies to ensure that we give you the best experience on our website. If you continue to use this site we will assume that you are happy with it.I AgreePrivacy policy