Cyber Security News

Google Fixes Actively Exploited Zero-day Vulnerability : Patch Now!

Google Chrome version 117.0.5938.132 for Windows, Mac, and Linux has been set to release with multiple bug fixes and features. As per Google, this new version will be rolled out in a few weeks or days.

Previously, Google has fixed multiple vulnerabilities in Chrome version 117.0.5938.62, which were associated with Insufficient policy enforcement, Inappropriate Implementation of Prompts, Inputs, Intents, and much more.

Document
FREE Demo

Deploy Advanced AI-Powered Email Security Solution

Implementing AI-Powered Email security solutions “Trustifi” can secure your business from today’s most dangerous email threats, such as Email Tracking, Blocking, Modifying, Phishing, Account Take Over, Business Email Compromise, Malware & Ransomware

Google Chrome Zero-day

As per the release from Google Chrome, 10 security fixes were issued along with three high-severity vulnerabilities as part of this release. The vulnerabilities were CVE-2023-5217, CVE-2023-5186, and CVE-2023-5187. The severity of these vulnerabilities is being analyzed for categorization by the National Vulnerability Database (NVD).

However, CVE-2023-5217 is known to have been exploited in the wild. This was a Heap buffer overflow vulnerability that existed in the vp8 encoding in libvpx. Google provided no further information about this vulnerability. 

CVE-2023-5186 was a Use-after-free condition in the Passwords, and CVE-2023-5187 was another Use-after-free condition in Extensions of Google Chrome. 

Proof of concept is not yet publicly available for these vulnerabilities. However, as for the rewards, CVE-2023-5187 has been rewarded with $2000, whereas the other two vulnerabilities’ reward details were yet to be released by Google. In addition to this, several internal audits and fuzzing-related fixes were also done as part of this release. 

“Access to bug details and links may be kept restricted until a majority of users are updated with a fix. We will also retain restrictions if the bug exists in a third-party library that other projects similarly depend on, but haven’t yet fixed.” reads the security release by Google.

Users of Google Chrome are recommended to upgrade to the latest version of Google Chrome to prevent these vulnerabilities from getting exploited by threat actors.

Protect yourself from vulnerabilities using Patch Manager Plus to quickly patch over 850 third-party applications. Take advantage of the free trial to ensure 100% security.

Eswar

Eswar is a Cyber security reporter with a passion for creating captivating and informative content. With years of experience under his belt in Cyber Security, he is reporting data breach, Privacy and APT Threats.

Recent Posts

CISA Red Team Breaches Critical Infrastructure to Reveal SOC and Cloud Security Gaps

CISA's latest advisory for red teams warns critical infrastructure operators that security systems can fail…

5 hours ago

AI Security Startup Alice Raises $140 Million as Enterprise AI Threats Surge

Alice, the AI trust, safety, and security company formerly known as ActiveFence, has closed a…

6 hours ago

SynkLoader Mimic as IT Support Personnel Attacking Users Via Microsoft Teams

SynkLoader is using Microsoft Teams conversations to turn routine IT support requests into a route…

7 hours ago

ToxNetV2 Linux Botnet Uses NVIDIA AI to Generate Shell and Remote SSH Attack Actions

ToxNetV2 is a Linux botnet that shows how artificial intelligence can move closer to real…

7 hours ago

WhatsApp Passkeys Reach 1 Billion Users as Two-Step Verification Gets Stronger Passwords

WhatsApp has confirmed that more than 1 billion people now use passkeys to log into…

8 hours ago

ASOS Warns Customer Accounts Were Accessed Using Compromised Login Credentials

ASOS US Sales LLC reported unauthorized access to customer accounts using credentials obtained from outside…

8 hours ago