Free Republic
Browse · Search
General/Chat
Topics · Post Article

Skip to comments.

Google wants you to update Chrome right now (ZERO-DAY Exploit in Chrome Browser)
TechSpot ^ | Mar 7, 2019 | Dean Pennington

Posted on 03/08/2019 7:49:10 AM PST by dayglored

Bottom line: Google is urging Chrome users to update their browsers immediately after a zero-day exploit that could give hackers direct access to a user's OS has been found. The most recent version is 72.0.3626.121, and it's the version you want to be running to make sure you're safe from this exploit.

Google is urging users to update Chrome across all platforms after a critical vulnerability was discovered and patched.

The vulnerability exploits a security flaw known as CVE-2019-5786. The security flaw is a memory management issue in Chrome's FileReader which gives hackers the opportunity to inject and execute malicious code.

FileReader is a embedded program in most browsers that allows web apps to read the contents of a user's local file system. The vulnerability identified by Google allows malicious code to leave Chrome's security environment and run commands on the underlying OS.

Well-known Chrome security researcher Justin Schuh concisely addressed the urgency of this update on Twitter:

Also, seriously, update your Chrome installs... like right this minute. #PSA

— Justin Schuh (@justinschuh) March 6, 2019

Google is calling this a "zero-day" vulnerability, meaning that the bad guys figured out how to exploit it before the good guys were able to find and patch it.

The version of Chrome you should be running is 72.0.3626.121, released at the beginning of March 2019. To check your version number, type chrome://settings/help into the address bar. From there, you will be able to see your version number. Just going to that page will trigger an update check, and Chrome will prompt you to relaunch it when finished. You can also manually download the latest version of Chrome here.

Stay safe out there.


TOPICS: Business/Economy; Computers/Internet; Hobbies
KEYWORDS: chrome; google; windowspinglist; zeroday
Navigation: use the links below to view more comments.
first previous 1-2021-4041-47 last
To: dayglored
> ...The bug... is a use-after-free() programming blunder...

That's a really dumb mistake to make. It's frankly disturbing that Google isn't using a good code analysis tool to catch screwups like that.

41 posted on 03/08/2019 11:17:01 AM PST by dayglored ("Listen. Strange women lying in ponds distributing swords is no basis for a system of government."`)
[ Post Reply | Private Reply | To 40 | View Replies]

To: dayglored

I got the update yesterday.
I saw on Suse’s page that it is unaffected by the problem.


42 posted on 03/08/2019 3:44:58 PM PST by Dalberg-Acton
[ Post Reply | Private Reply | To 1 | View Replies]

To: dayglored

chrome://settings/help

Gave “invalid site” message.


43 posted on 03/08/2019 4:59:32 PM PST by WildHighlander57 ((WildHighlander57 returning after lurking since 2000)
[ Post Reply | Private Reply | To 1 | View Replies]

To: bitt
Why anyone would have anything to do with Google is beyond me. From their beginning they were designing ways for the ChiComs to monitor citizen's browsing... why not Americans also? Why not everyone? Why design two different systems? Cheaper to design one - and use that tracking data to sell to advertisers, to information services, to governments.

Dirty from the beginning. Hey, Eric! How about setting up a server in H3ll?

44 posted on 03/08/2019 8:07:04 PM PST by Bob Ireland (The Democrat Party is a criminal enterprise)
[ Post Reply | Private Reply | To 17 | View Replies]

To: WildHighlander57
> chrome://settings/help Gave “invalid site” message.

Huh, dunno. Worked for me (Chrome browser running on MacOS). Haven't tried it on my Windows box yet...

45 posted on 03/08/2019 8:24:15 PM PST by dayglored ("Listen. Strange women lying in ponds distributing swords is no basis for a system of government."`)
[ Post Reply | Private Reply | To 43 | View Replies]

To: 109ACS; AbolishCSEU; aimhigh; bajabaja; Bikkuri; Bobalu; Bookwoman; Bullish; Carpe Cerevisi; ...
Update Chrome browser - ANDROID PING!

Android Ping!
If you want on or off the Android Ping List, Freepmail me.

46 posted on 03/10/2019 6:04:51 PM PDT by ThunderSleeps ( Be ready!)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Reno89519

Chromium is the basic skeleton of Chrome, without all of the bloatware/spyware added. It is fully functional, just like Chrome.


47 posted on 03/11/2019 3:58:06 PM PDT by Bikkuri
[ Post Reply | Private Reply | To 19 | View Replies]


Navigation: use the links below to view more comments.
first previous 1-2021-4041-47 last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
General/Chat
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson