Mar. 7th, 2019

charisstoma: (Default)


This is more recent:
The fix is included in Chrome 72.0.3626.121 for Android and desktop platforms.
https://www.androidpolice.com/2019/03/06/update-your-browser-right-now-google-releases-fix-for-zero-day-exploit-in-chrome/

And then there's...
https://www.welivesecurity.com/2019/03/07/latest-chrome-update-plugs-zero-day-hole/

Google has revealed that the update for Google Chrome,
https://chromereleases.googleblog.com/2019/03/stable-channel-update-for-desktop.html
, rolled out late last week, addressed a security hole that attackers were already exploiting in the wild.

“Google is aware of reports that an exploit for CVE-2019-5786 exists in the wild,” the company noted in an update on Tuesday after initially releasing the advisory last Friday. Also on Tuesday, a tweet by leading Chrome security engineer Justin Schuh added urgency to the issue: “[Like], seriously, update your Chrome installs… like right this minute”.

The vulnerability that affects the browser in Windows, Mac, and Linux was reported by Clement Lecigne of Google’s Threat Analysis Group on February 27.

The security hole is a “use-after-free” memory corruption bug in the browser’s FileReader API, a browser component intended to enable web apps to read locally stored files. That said, exploitation of the vulnerability can result in more damage than the API’s name might imply. As revealed by a note by the Center for Internet Security (CIS), attackers may ultimately be able to remotely execute arbitrary code on the targeted system:

“Depending on the privileges associated with this application, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights,” reads the note. The zero-day can be triggered when a user is lured to a specially crafted web page.

In light of all that, users are advised to update to Chrome version 72.0.3626.121 if they haven’t done so already. Arguably the easiest way to check if an update is pending is to type chrome://settings/help into the browser’s address bar and, if your browser is indeed out of date, follow the prompts.
charisstoma: (Default)
Quilting Craziness 2019
March 1, 2019 By andrew 2 Comments
Celebrate your favorite hobby all month long because March is National Quilting Month! We’re celebrating by making quilts, hosting a Missouri Star Employee quilt exhibit in Hamilton, and holding the very first “Quilting Craziness” tournament!

We invite everyone everywhere to participate everyday in the Quilting Craziness tournament!
NORTH STAR




Profile

charisstoma: (Default)
charisstoma

April 2019

S M T W T F S
  12 34 5 6
7 8 9 1011 1213
14 15 16 17 18 19 20
21222324252627
282930    

Most Popular Tags

Style Credit

Expand Cut Tags

No cut tags
Page generated Apr. 21st, 2019 04:47 pm
Powered by Dreamwidth Studios