India's cyber agency warns about bugs in Google Chrome for desktop


New Delhi, Aug 20 (IANS): The Indian Computer Emergency Response Team (CERT-In) has warned users about multiple vulnerabilities in Google Chrome for desktop that can let hackers gain access to their computers.

The multiple vulnerabilities could allow a remote attacker to execute arbitrary code and Security restriction bypass on the targeted system, according to an advisory by CERT-In, that comes under IT Ministry.

"These vulnerabilities exist in Google Chrome due to use after free in FedCM, SwiftShader, ANGLE, Blink, Sign-In Flow, Chrome OS Shell; Heap buffer overflow in Downloads, Insufficient validation of untrusted input in Intents, Insufficient policy enforcement in Cookies and Inappropriate implementation in Extensions API," the cyber agency said.

A hacker could exploit these vulnerabilities by sending specially crafted requests on the targeted system.

Successful exploitation of these vulnerabilities could allow a remote attacker to execute arbitrary code and Security restriction bypass on the targeted system, said CERT-In.

"The vulnerability (CVE-2022-2856) is being exploited in the wild. The users are advised to apply patches urgently," said the agency.

CERT-In also warned about bugs in Apple iOS, iPadOS and macOS and a "remote attacker could exploit this vulnerability by enticing a victim to open a specially-crafted file".

It also found multiple vulnerabilities in Cisco products again, which could allow the attacker to execute arbitrary code, information disclosure and cross site scripting attack on an affected system.

The nation's premier cyber agency had alerted about bugs in Cisco products in the recent past too.

 

  

Top Stories


Leave a Comment

Title: India's cyber agency warns about bugs in Google Chrome for desktop



You have 2000 characters left.

Disclaimer:

Please write your correct name and email address. Kindly do not post any personal, abusive, defamatory, infringing, obscene, indecent, discriminatory or unlawful or similar comments. Daijiworld.com will not be responsible for any defamatory message posted under this article.

Please note that sending false messages to insult, defame, intimidate, mislead or deceive people or to intentionally cause public disorder is punishable under law. It is obligatory on Daijiworld to provide the IP address and other details of senders of such comments, to the authority concerned upon request.

Hence, sending offensive comments using daijiworld will be purely at your own risk, and in no way will Daijiworld.com be held responsible.