Posted on 03/08/2019 7:49:10 AM PST by dayglored
Google is urging users to update Chrome across all platforms after a critical vulnerability was discovered and patched.
The vulnerability exploits a security flaw known as CVE-2019-5786. The security flaw is a memory management issue in Chrome's FileReader which gives hackers the opportunity to inject and execute malicious code.
FileReader is a embedded program in most browsers that allows web apps to read the contents of a user's local file system. The vulnerability identified by Google allows malicious code to leave Chrome's security environment and run commands on the underlying OS.
Well-known Chrome security researcher Justin Schuh concisely addressed the urgency of this update on Twitter:
Also, seriously, update your Chrome installs... like right this minute. #PSA
Justin Schuh (@justinschuh) March 6, 2019
Google is calling this a "zero-day" vulnerability, meaning that the bad guys figured out how to exploit it before the good guys were able to find and patch it.
The version of Chrome you should be running is 72.0.3626.121, released at the beginning of March 2019. To check your version number, type chrome://settings/help into the address bar. From there, you will be able to see your version number. Just going to that page will trigger an update check, and Chrome will prompt you to relaunch it when finished. You can also manually download the latest version of Chrome here.
Stay safe out there.
That's a really dumb mistake to make. It's frankly disturbing that Google isn't using a good code analysis tool to catch screwups like that.
I got the update yesterday.
I saw on Suse’s page that it is unaffected by the problem.
chrome://settings/help
Gave “invalid site” message.
Dirty from the beginning. Hey, Eric! How about setting up a server in H3ll?
Huh, dunno. Worked for me (Chrome browser running on MacOS). Haven't tried it on my Windows box yet...
Chromium is the basic skeleton of Chrome, without all of the bloatware/spyware added. It is fully functional, just like Chrome.
Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.