Security Update On Google Chrome Browser

Risk:
high
Damage:
high
Platform(s):
Chrome OS Google
Advisory ID:
ngCERT-2024-0004
Version:
N/A
CVE:
CVE-2024-1060, CVE-2024-1059, CVE-2024-1077
Published:
February 13, 2024

Summary


Security researchers discovered three high-severity vulnerabilities in the Google Chrome browser (CVE-2024-1060, CVE-2024-1059, and CVE-2024-1077). According to reports, the vulnerabilities might allow threat actors to remotely exploit Chrome, potentially executing arbitrary code, stealing sensitive user data, or causing system crashes. Meanwhile, Google has released new security updates to address many vulnerabilities in its Chrome browser. Nonetheless, users must take proper actions to mitigate dangers.

Description & Consequence


The high severity vulnerabilities have been classified as Use-After-Free (UAF), which is a vulnerability scenario resulting from inefficient memory management while developing software applications. For instance, If after freeing a memory location, a program does not clear the pointer to that memory, an attacker can use the error to hack the program. The UAF flaws were identified as (CVE-2024-1060, CVE-2024-1059 and CVE-2024-1077) respectively, found in the Canvas component, WebRTC component and Network component of Google Chrome. These flaws can allow an attacker to exploit heap corruption via a specially crafted HTML page, exploit stack corruption via a crafted HTML page and facilitate the remote exploitation of heap corruption via a malicious file. The affected systems are Chrome prior to 121.0.6167.139/140 for Windows and Chrome prior to 121.0.6167.139 for Mac and Linux.

Successful exploitation of these vulnerabilities could allow for the following:

  1. Arbitrary code execution in the context of the logged-on user.
  2. Depending on the privileges associated with the user, an attacker could install malicious programs.
  3. Attacker could view, change, steal or delete user data.
  4. Attacker could also create new accounts with full user rights.
  5. Attacker could also cause system crashes.

Solution


The aforementioned vulnerabilities have been patched by security update released by Google. Therefore, all users are encouraged to:

  1. Install the most recent updates for their systems, software, and gadgets.
  2. Remove saved login information or passwords, clear your browser's history.
  3. Remove cookies from your browser since they can provide hackers access to email services without a user's credentials.
  4. Refrain from clicking on dubious links that can corrupt your browsers.

Reference


Revision


Related Articles