News: 1650026977

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Google issues third emergency fix for Chrome this year

(2022/04/15)


Google is issuing fixes for two vulnerabilities in its Chrome web browser, including one flaw that is already being exploited in the wild.

The [1]emergency updates the company issued this week impact the almost 3 billion users of its Chrome browser as well as those using other Chromium-based browsers, such as Microsoft Edge, Brave and Vivaldi.

It is the third such emergency update Google has had to issue for Chrome this year.

[2]

One of the flaws is a [3]type confusion vulnerability tracked as CVE-2022-1364, a high-severity, zero-day bug that is actively being used by attackers. With a type confusion flaw, a program will allocate a resource like a pointer or object using one type but later will access the resource using another, incompatible type. In some languages, like C and C++, the vulnerability can result in out-of-bounds memory access.

[4]

[5]

This incompatibility can cause a browser to crash or trigger logical errors. However, if exploited, it could enable a hacker to execute arbitrary code.

"Depending on the privileges associated with the application, an attacker could view, change, or delete data," according to the [6]Center for Internet Security . "If this application has been configured to have fewer user rights on the system, exploitation of the most severe of this vulnerability could have less impact than if it was configured with administrative rights."

[7]

Google in its alert calls the vulnerability a type confusion in Chromium V8, impacting the JavaScript engine used in the browser.

Clement Lecigne, who is part of Google's Threat Analysis Group (TAG), reported the vulnerability on April 13 and the company announced the fix the same day.

"Google is aware that an exploit for CVE-2022-1364 exists in the wild," the company wrote in the alert.

[8]AI-powered browser extension to automatically click away cookie pop-ups now promised

[9]Google unrolls search features to tackle misinformation

[10]Microsoft updates Edge's Internet Explorer mode

[11]Microsoft backtracks on lack of easy Windows browser choice

Google officials did not release many details about the flaw, saying that information and links about the bug are being restricted until a majority of users are updated with the fix, which will bring Chrome to version 100.0.4896.127 across the Windows, Linux and Mac platforms. They also said they "will retain restrictions if the bug exists in a third party library that other projects similarly depend on, but haven't yet fixed."

The Chrome updates will be applied in the coming days and weeks, with Chrome automatically installing them when the browser is closed and relaunched.

[12]

Google should be getting used to issuing such emergency fixes. In March, both Google and Microsoft [13]issued updates to fix a vulnerability to the Chromium V8 JavaScript engine that was being actively exploited. That vulnerability, tracked as CVE-2022-1096, also was a high-severity bug in Chrome, Edge and other browsers.

A month earlier, Google threat researchers found a flaw that was being abused in the while, saying it was being exploited as early as Jan. 4. In a [14]report in March, the TAG team said two North Korean-based threat groups were exploiting a remote code execution (RCE) vulnerability in Chrome tracked as CVE-2022-0609 in campaigns dubbed Operation Dream Job and Operation AppleJeus.

The attacks focused on US-based organizations in such sectors as the news media, IT, financial tech and cryptocurrency, though the researchers said other companies in other countries also may have been targeted.®

Get our [15]Tech Resources



[1] https://chromereleases.googleblog.com/2022/04/stable-channel-update-for-desktop_14.html

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YlmWsaWqlYCoCutunR9OvgAAARE&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[3] https://cwe.mitre.org/data/definitions/843.html

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YlmWsaWqlYCoCutunR9OvgAAARE&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YlmWsaWqlYCoCutunR9OvgAAARE&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[6] https://www.cisecurity.org/advisory/a-vulnerability-in-google-chrome-could-allow-for-arbitrary-code-execution_2022-055

[7] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YlmWsaWqlYCoCutunR9OvgAAARE&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[8] https://www.theregister.com/2022/04/12/cookie_consent_is_broken_and/

[9] https://www.theregister.com/2022/03/31/google_misinfo_features/

[10] https://www.theregister.com/2022/03/30/ie_mode_changes/

[11] https://www.theregister.com/2022/03/29/microsoft_browser_choice/

[12] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YlmWsaWqlYCoCutunR9OvgAAARE&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[13] https://www.theregister.com/2022/03/28/google_chromium_exploit/

[14] https://blog.google/threat-analysis-group/countering-threats-north-korea/

[15] https://whitepapers.theregister.com/



How happy I am

WolfFan

That I use Firefox and Safari.

Re: How happy I am

Anonymous Coward

So you use two browsers that could potentially have insecurities or flaws. Divide and conquer yourself. I love your thinking. You truly are too wise for my tiny mind.

Re: How happy I am

LDS

Still, it good to have alternatives that doesn't use all the same code. If a bug is actively exploited and dangerous, you can switch to an alternative for a while.

Re: How happy I am

Claverhouse

So your conclusion is to use no browser at all ?

Re: How happy I am

bombastic bob

practice "safe surfing". One aspect already mentioned, NOT surfing the web with administrator privileges

I go one step further - do not surf the web on a WINDOWS computer (and use NoScript type plugins whenever possible, especially when following links to sites you have not been to before and do not already trust and even THEN, limit what runs or sandbox the browser)

that, and not reading mail in HTML form - text only (does Micros~1 mail program use the chrome engine to display HTML mail? yeah NOBODY ever e-mails spam with vulnerabilities and/or script in them)

anyway, captain obvious for the rest of it

Re: How happy I am

VoiceOfTruth

-> practice "safe surfing".

In practice this is impossible if you are going to browse the web at all. Practically every site these days slurps in great chunks of javascript from third-party web sites. You think you are being sensible browsing to somesafewebsite.com, but in the background it has included all manner of junk without you knowing about it (unless you look).

Type confusion

Mike 137

Almost always, 'type confusion' results from developer inattention. However any decent method library should trap such errors. Way back (40 odd years ago) we were writing validation wrappers around 'hazardous' C functions to do just that. The practice seems to have fallen by the wayside.

Re: Type confusion

IGotOut

That's because companies like to hire fresh talent and sack the old crusties with their crazy stuck in the mud ideas.

Therefore the bright young things make exactly the same mistakes that the old farts learnt to avoid a long time ago.

Anonymous Coward

"The Chrome updates will be applied in the coming days and weeks, with Chrome automatically installing them when the browser is closed and relaunched."

Which, of course, no-one in their right mind would allow. If I'm on a customer's network, the last thing I want to do is download updates or have some dumbass application decide to download them on its own.

It's a good thing we don't get all the government we pay for.