Time to Update: Google Patches 2 Severe Zero-Day Chrome Vulnerabilities

Time to Update: Google Patches 2 Severe Zero-Day Chrome Vulnerabilities

A spate of zero-day attacks have hit Google’s Chrome browser in the last few weeks, and you can add two more to the list. Google released a patch this week to fix the security flaws in its browser, but we don’t know exactly what the flaws are. Unlike the last few zero-days, Google didn’t find these security holes itself. Instead, it was tipped by anonymous third-parties, and the problems are severe enough that it hasn’t released full details. Suffice it to say, you should stop putting off that update.

Google’s internal security team is constantly trying to break Chrome in order to uncover potential bugs before they become the basis for a harmful malware campaign. And indeed, Google catches a lot of glitches and pushes out patches before anyone outside the company notices. A zero-day exploit is one that Google and the developer community didn’t catch, and could therefore leave millions of machines open to attack.

We usually get details on patches in Chrome, but Google has temporarily withheld details of these latest flaws because both have been used in the wild as attack vectors. One of the flaws, CVE-2020-16013, is related to Google’s V8 JavaScript engine. The second is CVE-2020-16017, and this one is a “use after free” problem in memory management that allows code to leak out of Chrome’s Site Isolation sandbox.

Time to Update: Google Patches 2 Severe Zero-Day Chrome Vulnerabilities

Without more details, we can’t say if these bugs are any more severe than the others we’ve seen lately. However, they could have a much greater impact simply by virtue of the fact that internet ne’er-do-wells figured out how to exploit them before Google even knew there was a problem.

You’re protected as long as you’re on Chrome version 86.0.4240.198 or higher. You can check on that in Settings > Help > About Chrome. If you haven’t updated yet, you might have a nagging “update” badge at the top of Chrome right now. Just give in. These are serious bugs that are being actively used to take over computers. Granted, high-value vulnerabilities like these are usually used to target a specific set of individuals. This still isn’t a chance you want to take, and the details of these vulnerabilities won’t stay secret forever. You don’t want to be running an old version of Chrome when the details are widely known.

Continue reading

Chromebooks Gain Market Share as Education Goes Online
Chromebooks Gain Market Share as Education Goes Online

Chromebook sales have exploded in the pandemic, with sales up 90 percent and future growth expected. This poses some challenges to companies like Microsoft.

Scientists Confirm the Presence of Water on the Moon
Scientists Confirm the Presence of Water on the Moon

Scientists have confirmed the discovery of molecular water on the moon. Is there any of it in a form we can use? That's less clear.

Review: The Oculus Quest 2 Could Be the Tipping Point for VR Mass Adoption
Review: The Oculus Quest 2 Could Be the Tipping Point for VR Mass Adoption

The Oculus Quest 2 is now available, and it's an improvement over the original in every way that matters. And yet, it's $100 less expensive than the last release. Having spent some time with the Quest 2, I believe we might look back on it as the headset that finally made VR accessible to mainstream consumers.

Samsung, Stanford Built a 10,000 PPI Display That Could Revolutionize VR, AR
Samsung, Stanford Built a 10,000 PPI Display That Could Revolutionize VR, AR

Ask anyone who has spent more than a few minutes inside a VR headset, and they'll mention the screen door effect. This could eliminate it for good.