Google urges users to update Chrome to address zero-day vulnerability

[ad_1]

Google has released an emergency security update to Chrome to address a zero-day vulnerability targeted by an exploit already circulating on the Internet that could allow malicious code to execute.

Google urges users to update Chrome to the new version, 112.0.5615.121, as soon as possible. The updated version addresses the vulnerability, which affects Windows, Mac and Linux systems, and is listed as CVE-2023-2033 in the US National Vulnerability Database.

Meanwhile, the update will roll out to Google’s stable desktop channel in the coming weeks, the company said.

The high-severity vulnerability was described by Google as a “type confusion” issue in the V8 JavaScript engine. Google Chrome V8 is Google’s open source JavaScript and WebAssembly engine.

“Google is aware that an exploit exists for CVE-2023-2033,” the company said in an April 14 statement.

NIST, the US Department of Commerce agency that maintains the National Vulnerability Database, went further in its CVE description of the vulnerability. Type confusion in V8 in Google Chrome before 112.0.5615.121 allowed a remote attacker to potentially exploit the heap corruption via a created HTML page, NIST said.

Google is yet to release full details about the vulnerability. Access to bug details and links may be limited until most users are updated with a fix, Google said in the statement.

How to update Chrome

To update Chrome, users can click on the overflow menu on the right side of the menu bar and then go to Help & About Google Chrome. Chrome will automatically check for browser updates and, by default, update your browser. Once the update is complete, users need to restart their browser.

Clement Lecigne of Google’s Threat Analysis Group identified the vulnerability and reported the issue on April 11. In addition to fixing CVE-2023-2033, the Chrome update also addresses a number of issues discovered during internal audits and other initiatives, the company said.

This is the first zero-day vulnerability reported in Chrome this year. In December, Google released an update for Chrome after a different type confusion vulnerability was identified in V8.

A type confusion error occurs when a program uses one type of method to allocate or initialize a resource but uses another method to access that resource, leading to an out-of-bounds memory access, according to computer security firm NSFocus, in a notice it sent about Chrome’s December update. “By convincing a user to visit a specially crafted website, a remote attacker could ultimately achieve arbitrary code execution or cause denial of service on the system,” NSFocus said.

Last year, 9 zero-day vulnerabilities were identified in Chrome.

In 2022, the number of known open source vulnerabilities increased by 4% compared to 2021, according to a report from Synopsys. At least one known open source vulnerability was found in 84% of all commercial and proprietary codebases reviewed by researchers, and 48% of all codebases reviewed contained high-risk vulnerabilities

Copyright © 2023 IDG Communications, Inc.

Sources

1/ https://Google.com/

2/ https://www.csoonline.com/article/3693259/google-urges-users-to-update-chrome-to-address-zero-day-vulnerability.html

The mention sources can contact us to remove/changing this article

[ad_2]

Leave a Reply

Your email address will not be published. Required fields are marked *

Related Posts