Indian cyber agency finds multiple bugs in Google Chrome, SAP Products


New Delhi, Jun 16 (IANS): The Indian Computer Emergency Response Team (CERT-In), which comes under the Ministry of Electronics & Information Technology, has warned users of vulnerabilities in Google Chrome for desktop and SAP Products, which could allow an attacker to execute arbitrary code or cause a denial of service condition on the targeted system.

The affected software in Google Chrome for desktop includes Chrome versions prior to 126.0.6478.54 for Linux and Chrome versions before 126.0.6478.56/57 for Windows and Mac.

On the other hand, the affected SAP products include SAP Financial Consolidation, NetWeaver AS Java (Meta Model Repository), NetWeaver AS Java (Guided Procedures), NetWeaver and ABAP platform, Document Builder (HTTP service), Bank Account Management, and others.

"Multiple vulnerabilities have been reported in Google Chrome which could allow a remote attacker to execute arbitrary code on the targeted system," said the CERT-In advisory.

As per the cyber agency, these vulnerabilities exist in Google Chrome due to Type Confusion in V8; Use after free in Dawn, V8, BrowserUI, Audio; Inappropriate implementation in Dawn, DevTools, Memory Allocator, Downloads; Heap buffer overflow in Tab Groups, Tab Strip and Policy Bypass in CORS.

A remote attacker could exploit these vulnerabilities by persuading a victim to visit a specially crafted web page. The vulnerabilities reported in SAP Products could allow an attacker to perform Cross-site scripting (XSS), Missing authorisation checks, File upload, obtain sensitive information, or cause denial of service conditions on the targeted system, according to the cyber agency.

CERT-In has suggested users apply appropriate security updates as recommended by the companies to stay away from phishing attacks.

 

  

Top Stories

Comment on this article

  • Sense_shetty, Kudla

    Sun, Jun 16 2024

    It's widely known that Chrome is riddled with bugs and notorious for data theft. In fact, most browsers, including Chrome and Edge, covertly track your data. Occasionally, India CERT issues advisories about these issues, seemingly just to remind us of their existence. Many government enterprise officials still use Gmail for email which is , a US-based service, which highlights our low standards and lack of concern for data privacy .

    DisAgree Agree [1] Reply Report Abuse


Leave a Comment

Title: Indian cyber agency finds multiple bugs in Google Chrome, SAP Products



You have 2000 characters left.

Disclaimer:

Please write your correct name and email address. Kindly do not post any personal, abusive, defamatory, infringing, obscene, indecent, discriminatory or unlawful or similar comments. Daijiworld.com will not be responsible for any defamatory message posted under this article.

Please note that sending false messages to insult, defame, intimidate, mislead or deceive people or to intentionally cause public disorder is punishable under law. It is obligatory on Daijiworld to provide the IP address and other details of senders of such comments, to the authority concerned upon request.

Hence, sending offensive comments using daijiworld will be purely at your own risk, and in no way will Daijiworld.com be held responsible.