Time to Update: Google Patches 2 Severe Zero-Day Chrome Vulnerabilities

A spate of zero-day attacks have hit Google’s Chrome browser in the last few weeks, and you can add two more to the list. Google released a patch this week to fix the security flaws in its browser, but we don’t know exactly what the flaws are. Unlike the last few zero-days, Google didn’t find these security holes itself. Instead, it was tipped by anonymous third-parties, and the problems are severe enough that it hasn’t released full details. Suffice it to say, you should stop putting off that update.
Google’s internal security team is constantly trying to break Chrome in order to uncover potential bugs before they become the basis for a harmful malware campaign. And indeed, Google catches a lot of glitches and pushes out patches before anyone outside the company notices. A zero-day exploit is one that Google and the developer community didn’t catch, and could therefore leave millions of machines open to attack.
We usually get details on patches in Chrome, but Google has temporarily withheld details of these latest flaws because both have been used in the wild as attack vectors. One of the flaws, CVE-2020-16013, is related to Google’s V8 JavaScript engine. The second is CVE-2020-16017, and this one is a “use after free” problem in memory management that allows code to leak out of Chrome’s Site Isolation sandbox.

Without more details, we can’t say if these bugs are any more severe than the others we’ve seen lately. However, they could have a much greater impact simply by virtue of the fact that internet ne’er-do-wells figured out how to exploit them before Google even knew there was a problem.
You’re protected as long as you’re on Chrome version 86.0.4240.198 or higher. You can check on that in Settings > Help > About Chrome. If you haven’t updated yet, you might have a nagging “update” badge at the top of Chrome right now. Just give in. These are serious bugs that are being actively used to take over computers. Granted, high-value vulnerabilities like these are usually used to target a specific set of individuals. This still isn’t a chance you want to take, and the details of these vulnerabilities won’t stay secret forever. You don’t want to be running an old version of Chrome when the details are widely known.
Continue reading

Interview: NASA’s Adam Steltzner Talks Perseverance and Why We Shouldn’t Colonize Mars
NASA's Perseverance rover is set to touch down on Mars in the coming days, and we had the opportunity to talk to one of the people who had a hand in bringing this mission to fruition.

WATCH: Perseverance Lands on Mars Today in ‘7 Minutes of Terror’
It's almost time for Perseverance to join Curiosity on the surface of Mars. Here's how to watch the landing.

NASA’s Perseverance Rover Successfully Lands on Mars
NASA used Curiosity as a model for this new robot, but its instrument suite is upgraded to scour the red planet for signs of ancient life. This mission will also be the first leg in a three-part process to get bits of Mars back to Earth for more intense study. And it all starts today.

NASA Releases Incredible Perseverance Rover Landing Video
NASA's Perseverance rover has been on the surface of Mars for several days, giving the team here on Earth time to run system checks and download preliminary data from the robot. The agency has now released the first large batch of media from the mission, including hundreds of still images and the first video and audio ever recorded on Mars.