Application and softwareScience and Technology

Identification of Chrome vulnerabilities by Google



Google has released an update for eight security vulnerabilities in its Chrome browser. One of these defects is a high-intensity zero-day vulnerability with the ID CVE-2022-0609, which is actively exploited in real attacks and is considered as the first zero-day vulnerability patched by this large company in 2022. Taken.

According to Aetna from ISNA, the vulnerability of day zero means that no solution has been provided for it so far or you have zero chance to find a solution. One of the criteria for supporting malware is the high number of zero days in which it is supported. Most Zero Day vulnerabilities are discovered and exploited by hacker groups backed by governments or large terrorist groups.

On the other hand, users’ inattention to antivirus and browser updates causes systems to become infected with malware, leading to the loss of stored information. Victims of cyberspace inadvertently by opening attachments to spam emails or links within them, opening infected downloaded files from unreliable sites or clicking on malicious links, by distributing infected advertisements, by hacking and infiltrating systems; Especially systems whose vulnerabilities are not patched are being exploited.

The Skills Center (PC Incident Management) announced that all versions before Google Chrome 98.0.4758.102 are affected by the following vulnerabilities. Therefore, Google Chrome users are advised to update their Chrome browser to 98.0.4758.102 on Windows, Mac, or Linux to reduce any potential threats.

CVE-2022-0603: Use-after-free vulnerability in file management, high intensity.

CVE-2022-0604: High Grip Hip Buffer Overflow Vulnerability in Tab Groups.

CVE-2022-0605: Use-after-free vulnerability in Webstore API, high intensity.

CVE-2022-0606: Use-after-free vulnerability in ANGLE, high intensity.

CVE-2022-0607: Use-after-free vulnerability in GPU, high intensity.

CVE-2022-0608: High-intensity integer overflow vulnerability in Mojo.

CVE-2022-0609: Use-after-free vulnerability in Animation, high intensity.

CVE-2022-0610: Inadequate implementation vulnerability in Gamepad API, moderate intensity.

Leave a Reply

Back to top button