Google Chrome seeks second security patch for zero day vulnerability
By MYBRANDBOOK
Google chrome has introduced a new security update on desktops. The new patch manages fixes to a total of 10 bugs in the browser, including zero-day vulnerability - the second to have been noticed by Google's Threat Analysis Group (TAG) that tracks threat actors in the last two weeks.
Google has refused to reveal any details of the bug and links till a majority of Chrome users have installed the update and the vulnerabilities are also fixed in any related third-party library.
A zero-day vulnerability refers to a recently discovered software security flaw that could have been already exploited by hackers.
For the systems running on Windows, Mac, and Linux, the Google Chrome security patch version 86.0.4240.183 is being released.
In a blogpost published on Chrome, Google said that it was aware of reports that an exploit of the particular zero-day vulnerability identified as CVE-2020-16009 exists in the wild. The changelog of the update only has a passing mention that the zero-day bug was in V8 - an open-source JavaScript engine designed for Google Chrome and is also used by other Chromium browsers, such as Microsoft Edge and Opera.
The zero-day issue that the latest patch fixes is the second to be spotted in the last two weeks and the fourth in the last 12 months.
A security patch was released by Google to fix CVE-2020-15999 - an actively exploited memory corruption bug in the FreeType font rendering library within Chrome.
A few days after releasing a security patch to fix it, Google on October 30 revealed that the zero-day CVE-2020-15999 was being exploited in conjunction with a windows zero-day vulnerability identified as CVE-2020-17087.
While the malicious code was being executed inside Google Chrome, the Windows zero-day was increasing the code's privileges to attack the Windows OS. Ben Hawkes, the technical lead of Google's Project Zero, an elite team of bug hunters, has said that Microsoft is expected to issue a security patch to fix their security flaw on November 10.
While Google's TAG did not reveal if the two bugs were being exploited by the same threat actors, it confirmed that the motive of the attackers was unrelated to the US presidential elections.
Nazara and ONDC set to transform in-game monetization with ‘
Nazara Technologies has teamed up with the Open Network for Digital Comme...
Jio Platforms and NICSI to offer cloud services to government
In a collaborative initiative, the National Informatics Centre Services In...
BSNL awards ₹5,000 Cr Project to RVNL-Led Consortium
A syndicate led by Rail Vikas Nigam Limited (abbreviated as RVNL), along wi...
Pinterest tracks users without consent, alleges complaint
A recent complaint alleges that Pinterest, the popular image-sharing platf...
TEJAS NETWORKS INDIA PVT. LTD.
DELL TECHNOLOGIES INDIA PVT. LTD.
GLOBUS INFOCOM LTD.
SECUREYE SERVICES PVT. LTD.
Icons Of India : Harsh Jain
Harsh Jain, the co-founder of Dream 11, the largest fantasy sports web...
ICONS OF INDIA : SUNIL VACHANI
Sunil Vachani is the Chairman of Dixon Technologies (India) Ltd. Under...
Icons Of India : Dilip Asbe
At present, Dilip Asbe is heading National Payments Corporation of Ind...
RailTel Corporation of India Limited
RailTel is a leading telecommunications infrastructure provider in Ind...
BEL - Bharat Electronics Limited
BEL is an Indian Government-owned aerospace and defence electronics co...
CERT-IN - Indian Computer Emergency Response Team
CERT-In is a national nodal agency for responding to computer security...
Indian Tech Talent Excelling The Tech World - ARVIND KRISHNA, CEO – IBM
Arvind Krishna, an Indian-American business executive, serves as the C...
Indian Tech Talent Excelling The Tech World - Sanjay Mehrotra, CEO- Micron Technology
Sanjay Mehrotra, the President and CEO of Micron Technology, is at the...
Indian Tech Talent Excelling The Tech World - Aman Bhutani, CEO, GoDaddy
Aman Bhutani, the self-taught techie and CEO of GoDaddy, oversees a co...