CERT-In Alerts Users of High-Risk Vulnerabilities in Google Chrome, Check Details
India 's Computer Emergency Response Team (CERT-In) has issued a warning regarding multiple 'high' risk vulnerabilities discovered in Google Chrome , identified as CVE-2024-1283 and CVE-2024-1284.
These vulnerabilities pose a significant threat as they can be exploited by remote attackers to execute arbitrary code, potentially leading to a denial of service (DoS) attack and the unauthorized access of sensitive information on the target system.
According to CERT-In, the vulnerabilities stem from 'Use after free in Mojo' and 'Heap buffer overflow in Skia' within Google Chrome. Remote attackers can leverage these weaknesses by sending specially crafted requests to the targeted system.
The vulnerabilities impact Google Chrome versions 122.0.6167.160/161 for Windows and versions 122.0.6167.160 for Mac and Linux, and versions prior to these.
To safeguard against potential exploitation, users are strongly advised to promptly download and install the latest software updates for Google Chrome available for their respective platforms. Google has provided a list of security fixes accompanying the stable channel update.
In addition to the Google Chrome vulnerabilities, CERT-In recently warned users about security flaws discovered in the Android operating system. These vulnerabilities affect Android versions 11, 12, 13, and 14, with vulnerabilities found within various framework components including MediaTek , Unisoc, and Qualcomm components. Users are urged to stay vigilant and apply necessary updates to mitigate potential risks to their devices and data.
- Understanding the Risk
These vulnerabilities pose a significant threat as they can be exploited by remote attackers to execute arbitrary code, potentially leading to a denial of service (DoS) attack and the unauthorized access of sensitive information on the target system.
According to CERT-In, the vulnerabilities stem from 'Use after free in Mojo' and 'Heap buffer overflow in Skia' within Google Chrome. Remote attackers can leverage these weaknesses by sending specially crafted requests to the targeted system.
You may also like
- Trump renames AI as 'Superintelligence'
- BGMI Gully Wars announced: Registration deadline, qualifier dates and prize pool
- Piyush Goyal calls for strengthening export facilitation via physical and digital mechanisms
- Centre to roll out new incentive scheme soon to boost lithium, nickel production
- Cred alumni's Sol raises $4 million from GC, Nexus Venture Partners, Kunal Shah
- Affected Users and Protective Measures
The vulnerabilities impact Google Chrome versions 122.0.6167.160/161 for Windows and versions 122.0.6167.160 for Mac and Linux, and versions prior to these.
To safeguard against potential exploitation, users are strongly advised to promptly download and install the latest software updates for Google Chrome available for their respective platforms. Google has provided a list of security fixes accompanying the stable channel update.
- Recent Alerts and Related Concerns
In addition to the Google Chrome vulnerabilities, CERT-In recently warned users about security flaws discovered in the Android operating system. These vulnerabilities affect Android versions 11, 12, 13, and 14, with vulnerabilities found within various framework components including MediaTek , Unisoc, and Qualcomm components. Users are urged to stay vigilant and apply necessary updates to mitigate potential risks to their devices and data.





