Google Chrome users have been warned by the Indian government’s cybersecurity agency, CERT-In (Indian Computer Emergency Response Team). The agency found numerous vulnerabilities in Google Chrome versions before 122.0.6261.11/2 for Windows and Mac. The current advisory note, CIVN-2024-0085, reported that these vulnerabilities are HIGH severity, indicating a high security risk to consumers.
Details about CIVN-2024-0085 vulnerability
A vulnerability in CERT-In Note CIVN-2024-0085 lists multiple Google Chrome browser vulnerabilities that could allow hackers to access sensitive data and take control of your system.
Technical details
According to the Indian government’s security advisory, these vulnerability may be in Google Chrome components like:
- FedCM: Prone to “Use-after-free” errors. Hackers can modify browser memory and execute code using this error.
- V8 (JavaScript engine): Has “Out-of-bounds memory access” and “inappropriate implementation.” This mistake lets hackers upload malware or crash the browser.
How Hackers Exploit These Vulnerabilities
Hackers can attack these vulnerabilities by sending a specially prepared webpage to the user, according to CERT-In. After the user visits the malicious webpage, cyber attackers can utilize Chrome vulnerabilities to do things like disable the system with a DoS attack or execute arbitrary code.
In Basic Terms:
- Hackers could exploit these vulnerabilities on any device to:
- Take Chrome’s personal, financial, and credential data.
- Install malware to damage your machine, steal data, or commit crimes.
- Take over your machine (a nightmare scenario where they can steal backups, data, and damage everything).
Google Deployed Security Updates
Google has provided Chrome browser security patches to combat these threats, which is good news despite the significant risk. Also, CERT-In recommends updating Google Chrome.
How to Update Google Chrome
Follow these procedures to update Google Chrome:
- Open Chrome.
- Click the top-right three vertical dots.
- Go to Settings
- Click ‘About Chrome’.
- Download and install updates (if they don’t start automatically).
- Once done, restart Chrome to update changes.