Clicky

AndroidPure
  • Leaks
  • News
  • Reviews
  • Updates
  • How to
No Result
View All Result
  • Leaks
  • News
  • Reviews
  • Updates
  • How to
No Result
View All Result
AndroidPure
No Result
View All Result

Google Chrome 107 emergency update patches 8th zero-day vulnerability in 2022

Ashwin Karthik by Ashwin Karthik
November 26, 2022
in Apps, News

A new emergency update is available for Google Chrome on desktop and Android. The update brings an important security fix for a zero-day vulnerability in the browser.

Google Chrome 107 emergency update patches 8th zero-day vulnerability in 2022

Google Chrome patches 8th zero-day exploit this year

The security issue, which has been tracked as CVE-2022-4135, has been labeled a high severity issue. As noted by Bleeping Computer, this is the 8th zero-day vulnerability that has been found in Chrome this year. That might be surprising, but considering that Chrome boasts the largest user base among browsers, it no doubt attracts more attention from hackers than the rest.

A blog post that has been published by Google describes the issue as a heap buffer overflow in the GPU. The flaw was reported by Clement Lecigne of Google’s Threat Analysis Group, on November 22nd. The announcement confirms that the vulnerability has been actively exploited by threat actors in the wild. The Mountain View company has not gone further into the details about the security loophole. The article explains that Google will restrict access to the bug details and links, until the update that contains a fix for the security flaw has rolled out to the majority of its users. That makes sense since the vulnerability has already been exploited, so disclosing more details about the attack vector right away can actually help in minimizing the number of attacks that target the loophole.

The CVE record for the issue sheds a little more light on how the issue could have impacted users. The vulnerability in the heap buffer overflow in the GPU, might have allowed hackers who had gained remote access to the renderer process in the web browser. This could then be used to perform a sandbox escape with a crafted HTML page. In simpler terms, a hacker could have executed malicious code from outside the sandbox’s protection, thus compromising the user’s security. The issue affects all versions of Chrome prior to version 107.0.5304.121.

The fix for this bug is included in the latest version of Google Chrome 107, more specifically 107.0.5304.121 and .122 for Windows, Mac and Linux. Google Chrome 107 (107.0.5304.141) for Android also includes the security patch. Chrome’s Extended Stable channel has been updated to 106.0.5249.199 on Windows and Mac, but it’s unclear if it contains the security fix.

Google’s announcement says that it may take a few days or weeks for the emergency update to roll out to all users. But when I checked it on my computer, the update was already available for the stable channel of the browser. If you don’t have it yet, go to the desktop program’s Menu > About Chrome page, and it should download and update to the new build automatically. Chrome users on Android can get the app update from the Google Play Store. Other browsers that rely on Chromium’s source code should hopefully pick up the security fix soon, and ship it an update to protect their users.

Google had patched 10 security issues in Chrome 107, which was released to the stable channel a few weeks ago.

Tags: ChromeGoogle
Previous Post

Lava Blaze NXT with Helio G37 launched in India

Next Post

Xiaomi 13 to launch on December 1st

Ashwin Karthik

Ashwin Karthik

Originally a Business Grad, Ashwin is a natural at testing and reviewing apps & games for Windows and Android Apps, as well as flashing ROMs. A proud owner of a Redmi K20, he is also an avid gamer and loves playing on his Computer, PS4 & Nintendo consoles.

Follow Us

  • 914 Followers

Popular

  • How to fix lags in Citra emulator on Android

    What is the Citra resolution hack? Learn how to improve FPS in 3DS games on your Android phone

    15 shares
    Share 14 Tweet 0
  • How to set up NextDNS on Android

    1 shares
    Share 0 Tweet 0
  • How to enable dual clock in MIUI lock screen and home screen

    1 shares
    Share 0 Tweet 0
  • How to fix pin required after phone restarts issue – random reboots?

    10 shares
    Share 9 Tweet 0
  • How to add a custom search engine in Firefox for Android

    1 shares
    Share 0 Tweet 0
  • ChatGPT app for Android is now available on Google Play

    1 shares
    Share 0 Tweet 0
  • Vivo V5 with 20 MP front camera with moonlight flash, 4 GB RAM launched for Rs. 17980

    1 shares
    Share 0 Tweet 0

Latest

POCO X6 NEO

Poco X6 Neo 5G unveiled, a Rebranded Redmi Note 13R Pro, in India

March 13, 2024
Realme 12+ 5G

Realme 12+ 5G, Realme 12 5G launched in India: Pricing, Specs, and Availability – All You Need to Know

March 6, 2024
Nothing Phone 2a

Nothing Phone 2a launched in India: Pricing, Specs, and Availability – All You Need to Know

March 6, 2024
IQoo Neo 9 Pro.png

iQoo Neo 9 Pro Launches in India: Snapdragon 8 Gen 2, 12GB RAM, and More

February 22, 2024
Oneplus 12r 256gb variant is also ufs 3 1 and not ufs 4 0 v0 mbzg2z9bxnhc1

Unpacking the OnePlus UFS 4.0 Controversy: Just it is UFS 3.1

February 13, 2024
Redmi Buds

Redmi Buds 5 Launched in India: Features, Price, and Availability

February 13, 2024
Moto G04

Motorola Announces Moto G04 Launch in India: A Budget Smartphone with Premium Features

February 11, 2024
AndroidPure

© 2024 AndroidPure - NonStop Android.

Navigate Site

  • Privacy
  • About Us
  • Tip Us
  • Contact Us

Follow Us

No Result
View All Result
  • Leaks
  • News
  • Reviews
  • Updates
  • How to

© 2024 AndroidPure - NonStop Android.