Skip to main content

CERT-In points out multiple Google Chrome vulnerabilities: What you need to know

The Indian Computer Emergency Response Team (CERT-In) has warned users about multiple vulnerabilities in Google Chrome for desktop that can let hackers gain access to their computers. The multiple vulnerabilities could allow a remote attacker to execute arbitrary code and Security restriction bypass on the targeted system, according to an advisory by CERT-In, that comes under IT Ministry. "These vulnerabilities exist in Google Chrome due to use after free in FedCM, SwiftShader, ANGLE, Blink, Sign-In Flow, Chrome OS Shell; Heap buffer overflow in Downloads, Insufficient validation of untrusted input in Intents, Insufficient policy enforcement in Cookies and Inappropriate implementation in Extensions API," the cyber agency said. A hacker could exploit these vulnerabilities by sending specially crafted requests on the targeted system. Successful exploitation of these vulnerabilities could allow a remote attacker to execute arbitrary code and Security restriction bypass on the targeted system, said CERT-In. "The vulnerability (CVE-2022-2856) is being exploited in the wild. The users are advised to apply patches urgently," said the agency. CERT-In also warned about bugs in Apple iOS, iPadOS and macOS and a "remote attacker could exploit this vulnerability by enticing a victim to open a specially-crafted file". It also found multiple vulnerabilities in Cisco products again, which could allow the attacker to execute arbitrary code, information disclosure and cross site scripting attack on an affected system. The nation's premier cyber agency had alerted about bugs in Cisco products in the recent past too.

(Except for the headline, the rest of this IANS article is un-edited)

For more technology news, product reviews, sci-tech features and updates, keep reading Digit.in.



from Apps News https://ift.tt/XYJQydT

Comments

Popular posts from this blog

Nothing just 5 Nothing Phone 2 details officially confirmed so far

Nothing Phone 2 could be semi-transparent or at least have a translucent charging cable. It won’t be a small phone either. Here’s everything we have learned about the phone from Carl Pei as well as leaks and rumours. Starting with what Carl Pei has hinted at in bits and pieces so far. Official Nothing Phone 2 hints and teasers 1. Semi-transparent USB-C cable pic.twitter.com/LOYjBLa5UZ — Carl Pei (@getpeid) June 19, 2023 So, the top portion of USB-C connector of Nothing Phone 2 sports the signature "transparent design language" of the brand. You can see the Nothing brandng through the transparent part. Carl calls it "nice" and we agree. It does look nice but we are concerned whether it will be discoloured in time.  2. Not a small phone Contrary to what we may believe living in the echo chamber, very few people buy small phones https://t.co/aVolitAzN3 — Carl Pei (@getpeid) June 18, 2023 Carl says not many people buy small phones. Generally, people prefer big di...