If you're an update laggard, buck up: Chrome zero-days are being exploited in the wild
- Reference: 1604520913
- News link: https://www.theregister.co.uk/2020/11/04/google_chrome_critical_updates/
- Source link:
Criminals are targeting users of Chrome with outdated installations, CISA said in an advisory note urging folk to update their browsers immediately.
"Google has released Chrome version 86.0.4240.183 for Windows, Mac, and Linux addressing multiple vulnerabilities, including vulnerability CVE-2020-16009. Exploit code for this vulnerability exists in the wild," said the agency in a statement.
The vuln affects the desktop version of Chrome and is a remote code execution bug publicly uncovered by Google's Project Zero infosec bods. It exists in V8, which is Google's [1]open-source JS and WebAssembly engine . Full details of the exploit are not yet in the public domain though the MITRE [2]entry for CVE-2020-16009 states, at the time of writing, that it "allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page".
Malicious people have clearly figured it out already despite the lack of information available to world+dog.
"Google is aware of reports that an exploit for CVE-2020-16009 exists in the wild," said the typically talkative Chocolate Factory.
Separate patches for the Android version of Chrome fix a similar actively exploited vuln tracked as CVE-2020-16010, explained only as a "heap buffer overflow in UI on Android".
Regardless of the scanty information – easily explained by Google, quite responsibly, not wanting to hand every script kiddie on the internet information on how to pwn slow-to-update folk – users of Chrome on Android should ensure they are running version 86.0.4240.185. ®
Get our [3]Tech Resources
[1] https://www.theregister.com/2020/10/02/google_javascript_fuzzing_funds/
[2] https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-16009
[3] https://whitepapers.theregister.com/
Tin foil hat brigade
What they really want is to scare everybody into updating to the latest version of Chrome that tracks everything you do to report back to the mothership, but is a little better at hiding that it is doing so...
This affects all Chromium browsers, there have been a number of updates applied to Vivaldi and Edge over the last few days.
What I find disappointing is that Chromium browsers don't always seem to update automatically, you have to go in to Help About to trigger the update in Edge which is pants really but I guess people get upset when Microsoft stuff auto updates. Vivaldi seems to check for updates on start up and then offer to apply whilst Firefox seems to be a bit more random. Don't know about Google Chrome as I don't use Google stuff if at all possible, but the fact that people are being told to update is not a good sign.
Google Responsibly
Regardless of the scanty information – easily explained by Google, quite responsibly, not wanting to hand every script kiddie on the internet information on how to pwn slow-to-update folk...
But not so much responsibly when reporting vulnerabilities in non-Google products: https://www.theregister.com/2020/11/03/google_project_zero_github_flaw_deadline/
Ha ha, I run Edge!
My hierarchy of commonly-installed browsers:
Firefox (with uBlock Origin, etc.) for most browsing
Edge for more relaxed browsing restrictions and Chrome compatibility
Chrome for when dipshit Web developers have explicitly coded their crap to Chrome exclusively
It's ironic that Edge is more secure than Chrome, don'cha think?