Google Patches Chrome Zero-Day Under Active Attack

  /     /     /  
Publicated : 23/11/2024   Category : security


Google Patches Chrome Zero-Day Under Active Attack


The fix addresses CVE-2019-13720, a high-severity, use-after-free vulnerability discovered by Kaspersky Lab researchers.



Google upped the ante for Halloween frights when it issued a Chrome browser update to patch two vulnerabilities, one of which is a high-severity zero-day being actively exploited in the wild.
Chrome version 78.0.3904.87 is for Windows, Mac, and Linux, and it will roll out over the coming days and weeks. It includes security fixes for CVE-2019-13721 and CVE-2019-13720, both of which it classifies as high-severity. Google is aware of reports that an exploit for CVE-2019-13720 exists in the wild, Googles Srinivas Sista wrote in a blog post on the update.
The vulnerability under attack is a use-after-free bug, a type of memory corruption flaw that attackers could use to execute malicious code. Google credits Anton Ivanov and Alexey Kulaev of Kaspersky Lab with discovering CVE-2019-13720, which the researchers reported on Oct. 29.
Access to bug details and links may be kept restricted until a majority of users are updated with a fix, Sista said. We will also retain restrictions if the bug exists in a third party library that other projects similarly depend on, but havent yet fixed.
The DHS Cybersecurity and Infrastructure Security Agency has issued an
advisory
on the patches, encouraging users and admins to review Chromes release and apply the updates.
Read more details
here
.
Check out 
The Edge
, Dark Readings new section for features, threat data, and in-depth perspectives. Todays top story:
Is Voting by Mobile App a Better Security Option or Just A Bad Idea?
.

Last News

▸ Nigerian scammers now turning into mediocre malware pushers. ◂
Discovered: 23/12/2024
Category: security

▸ Beware EMV may not fully protect against skilled thieves. ◂
Discovered: 23/12/2024
Category: security

▸ Hack Your Hotel Room ◂
Discovered: 23/12/2024
Category: security


Cyber Security Categories
Google Dorks Database
Exploits Vulnerability
Exploit Shellcodes

CVE List
Tools/Apps
News/Aarticles

Phishing Database
Deepfake Detection
Trends/Statistics & Live Infos



Tags:
Google Patches Chrome Zero-Day Under Active Attack