Details of these critical vulnerabilities are hidden. Clicking on the hyperlinks within the listed fixes may take you to a page with the message, “Permission denied.”
Another Chrome update to version 93.0.4577.82 for Windows, Mac and Linux.
Google didn’t go into detail as to what the latest fixes prevent. Of the 11 identified flaws, the company acknowledged at least two have been designated as zero-day exploits.
The latest zero-day exploits bring Google’s total to 10 critical patches just this year...
The Chrome stable release channel has been updated to 94.0.4606.81 for Windows.
Four fixes have been tagged as high severity and span several processes. Two have to do with heap buffer overflow in WebRTC and Blink, while the others fix a “Use after free in Garbage Collection” problem and “Inappropriate implementation in Sandbox."
Two of the flaws are considered zero-day exploits and mark the 13th such flaws this year. Hackers have also figured out a way to trick Windows into accepting code signatures that OpenSSL code could not detect in certain security clearance scanners.
And another Chrome update. Their Stable channel has been updated to 95.0.4638.69 for Windows.
CVE-2021-38000 is described as “Insufficient validation of untrusted input in Intents.”
CVE-2021-38003 is described as “Inappropriate implementation in V8.”
Google doesn’t explain how flaws like these can be exploited or for what purposes they can be used, but the total is now 15 zero-day exploits since the beginning of the year...
RoHe
12 Elder
•
45230 Posts
•
172625 Points
982
0
Posted September 17th, 2021 14:00
Another Chrome update to version 93.0.4577.82 for Windows, Mac and Linux.
Google didn’t go into detail as to what the latest fixes prevent. Of the 11 identified flaws, the company acknowledged at least two have been designated as zero-day exploits.
The latest zero-day exploits bring Google’s total to 10 critical patches just this year...