The Computer Emergency Response Team India (CERT-In) of the Ministry of Electronics and Information Technology has issued a warning to Google Chrome users. It reported several vulnerabilities in Google Chrome that could allow remote attackers to execute arbitrary code and bypass security restrictions on target systems.
No, not all Google Chrome users are affected by the vulnerability. According to the advisory, users of Google Chrome running versions prior to Google Chrome 104.0.5112.101 are at risk. If you are using an older version of Google Chrome, it is recommended to update the browser version on your laptop.
What does the warning say?
In its alert, CERT-In said it had identified several vulnerabilities in the Google Chrome browser that could "allow a remote attacker to execute arbitrary code and bypass security restrictions on the target system."
"Google Chrome has these vulnerabilities due to free post-use of FedCM, SwiftShader, ANGLE, Blink, Chrome OS shell login flow; buffer overflow during downloads, insufficient validation of untrusted input when attempted, applying insufficient cookie policies and incorrectly implementing extensions API."
The vulnerability (CVE-2022-2856) was exploited in the wild. Users are urged to apply the patches urgently, the advisory said.
Earlier this week, CERT-In issued an advisory to Apple users, warning that the vulnerability exists in iOS and iPadOS versions prior to 15.6.1 and in macOS Monterey versions prior to 12.5.1. . In its warning, the central agency said it could allow a remote attacker to exploit the vulnerability by instructing a victim to open a specially crafted file.
Apple has also disclosed serious security flaws for the iPhone, iPad and Mac, allowing attackers to gain complete control over these devices. The company said it was "aware of a report that this issue could be actively exploited," and asked its users to update its software. Apple has not released any information on the extent to which the issue has been exploited. The Cupertino-based company has already released two safety reports on the subject.

0 Comments