Free Republic
Browse · Search
General/Chat
Topics · Post Article

Skip to comments.

Google Pays Out $36,000 for Severe Chrome Vulnerability
SecurityWeek.com ^ | Wednesday 10/16/2024 | Ionut Arghire

Posted on 10/19/2024 1:34:28 AM PDT by linMcHlp

Google on Tuesday announced a fresh Chrome browser update that addresses 17 vulnerabilities, including 13 security defects reported by external researchers.

The most severe of the externally reported bugs is CVE-2024-9954, a high-risk use-after-free defect in AI . . .

The latest Chrome iteration is now rolling out as versions 130.0.6723.58/.59 for Windows and macOS, and as version 130.0.6723.58 for Linux.

(Excerpt) Read more at securityweek.com ...


TOPICS: Business/Economy; Computers/Internet
KEYWORDS: browser; security; vulnerability

1 posted on 10/19/2024 1:34:28 AM PDT by linMcHlp
[ Post Reply | Private Reply | View Replies]

To: linMcHlp

I try to keep it updated but sometimes am days or up to a week behind, with your reminder I just updated to the 130.0.6723.59


2 posted on 10/19/2024 1:53:17 AM PDT by ansel12 ((NATO warrior under Reagan, and RA under Nixon, bemoaning the pro-Russians from Vietnam to Ukraine.))
[ Post Reply | Private Reply | To 1 | View Replies]

To: linMcHlp

Google sucks.. everything about it sucks. Their vehicle infotainment systems are a disaster as well.


3 posted on 10/19/2024 2:28:26 AM PDT by maddog55 (The only thing systemic in America is the left's hatred of it!)
[ Post Reply | Private Reply | To 1 | View Replies]

To: linMcHlp

I like edge.


4 posted on 10/19/2024 2:45:01 AM PDT by roving (Deplorable Erectionists Listless Vessel )
[ Post Reply | Private Reply | To 1 | View Replies]

To: roving; ansel12; maddog55

Problem is within Chromium engine:

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-5274

Thus, affects:

- Brave Browser
- Microsoft Edge
- pthers


5 posted on 10/19/2024 3:24:01 AM PDT by linMcHlp
[ Post Reply | Private Reply | To 4 | View Replies]

To: linMcHlp; roving; ansel12; maddog55

“pthers” pi-tu-eee

others


6 posted on 10/19/2024 3:25:49 AM PDT by linMcHlp
[ Post Reply | Private Reply | To 5 | View Replies]

To: linMcHlp

My Brave keeps itself updated without my attention (but I checked anyway), and while I don’t use edge I did just open it and check for update because of your prompt.


7 posted on 10/19/2024 3:35:54 AM PDT by ansel12 ((NATO warrior under Reagan, and RA under Nixon, bemoaning the pro-Russians from Vietnam to Ukraine.))
[ Post Reply | Private Reply | To 6 | View Replies]

To: ansel12

I finally gave up and just use Edge - along with Windows Defender instead of other products.


8 posted on 10/19/2024 4:18:40 AM PDT by trebb (So many fools - so little time...)
[ Post Reply | Private Reply | To 2 | View Replies]

To: linMcHlp

I run Brave on windows as well as other browsers and mine reports version as 1.71.114 Chromium: 130.0.6723.58 (Official Build) (64-bit)

So, not sure if this is updated to the latest fix or not... it reports that it is updated to the newest but it is .58 not .59

Will switch to using another browser until I am sure...

My gaming PC still suffers from the Intel bug that causes CPU damage... have not received the latest update to firmware 0x12b so that PC sits idle :-/

groan


9 posted on 10/19/2024 4:45:25 AM PDT by Bobalu (I can’t even feign surprise anymore... And I am tired of the 🐂 💩!)
[ Post Reply | Private Reply | To 1 | View Replies]

To: trebb

“I finally gave up and just use Edge”

Edge came with my Windows 10 Dell. I don’t understand it; it won’t go away. I think I hate it. But Defender seems to do a good job.


10 posted on 10/19/2024 5:01:12 AM PDT by MayflowerMadam (I'm voting for the felon with the pierced ear. )
[ Post Reply | Private Reply | To 8 | View Replies]

To: linMcHlp

ADDITIONAL TROUBLE WITH CHROMIUM

There is a bug in Chromium that scrambles bookmarks.

Important: Maintain backups of Chromium-engined browser bookmarks - EXPORT to "bookmarks.html" file.

Bookmarks unusable since last update, blending together, changing when clicking on them, etc


11 posted on 10/19/2024 5:10:31 AM PDT by linMcHlp
[ Post Reply | Private Reply | To 1 | View Replies]

To: linMcHlp

What am I missing? The vulnerability is from late May 2024.


12 posted on 10/19/2024 5:47:04 AM PDT by CatOwner (Don't expect anyone, even conservatives, to have your back when the SHTF in 2021 and beyond.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: linMcHlp

I was responding to post #5.


13 posted on 10/19/2024 5:52:30 AM PDT by CatOwner (Don't expect anyone, even conservatives, to have your back when the SHTF in 2021 and beyond.)
[ Post Reply | Private Reply | To 12 | View Replies]

To: CatOwner
You are missing the article - the OP - the latest rollouts (this week of October, 2024) that apparently include fixes.

14 posted on 10/19/2024 6:28:50 AM PDT by linMcHlp
[ Post Reply | Private Reply | To 12 | View Replies]

To: trebb

Edge is based on Chromium now. MS gave up on making their own browser from scratch.


15 posted on 10/19/2024 6:37:17 AM PDT by Pollard (Will work for high tunnel money!)
[ Post Reply | Private Reply | To 8 | View Replies]

To: linMcHlp

Chromium is google’s open source version of Chrome.

“” Chromium has been a Google project since its inception,[1][3] and Google employees have done the bulk of the development work.[14] “”

I just stumbled on a browser I’d never heard of called LibreWolf. It’s based on Firefox with a focus on privacy and security.

“” According to the website PrivacyTests.org, LibreWolf, along with Brave Browser and Tor Browser, had the most privacy protection compared to other browsers.[16][17] “”

I’m currently migrating from Waterfox to LibreWolf. I also have Brave which I use for specific things, like logging into my bank’s web app.


16 posted on 10/19/2024 6:52:58 AM PDT by Pollard (Will work for high tunnel money!)
[ Post Reply | Private Reply | To 5 | View Replies]

To: Pollard
Brave Browser DEVELOPMENT

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

https://chromium.woolyss.com/?stb=1#windows-64-bit

Intrinsically, Chromium is a Google project maintained by many authors (developers, engineers, graphic designers, security researchers ... ) from Google, Adobe, Amazon, ARM, Brave, Cloudflare, Facebook, Hewlett-Packard, IBM, Igalia, Intel, Logitech, Microsoft, Mozilla, Nvidia, Opera, Samsung, Vivaldi, Xiaomi, Yandex ... and external contributors.

Chromium is not only a web browser. It is a blend of different important open-source projects:

ANGLE (Graphics engine abstraction layer)
  https://en.wikipedia.org/wiki/ANGLE_(software)

Blink (Rendering/layout engine)
  https://en.wikipedia.org/wiki/Blink_(browser_engine)

Native Client (Sandbox for running native code)
  https://en.wikipedia.org/wiki/Google_Native_Client

PDFium (PDF generation and rendering library)
  https://pdfium.googlesource.com/pdfium/

Sandbox (Security mechanism for separating running programs)
  https://chromium.googlesource.com/chromium/src/+/master/docs/design/sandbox.md

Skia (Graphics library)
  https://en.wikipedia.org/wiki/Skia_Graphics_Engine

V8 (JavaScript engine)
  https://en.wikipedia.org/wiki/Chrome_V8

and others . . .

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

Deviations from Chromium (features we [Brave] disable or remove)

    brave/brave-browser (at Github)

       https://github.com/brave/brave-browser/wiki/Deviations-from-Chromium-(features-we-disable-or-remove)

Chromium source is fetched

Brave code is fetched

Hooks are run

What Chromium features are removed for privacy/security reasons?

Services & Features We Disable Entirely

And much more at that Github site.

- - - - - - - - -

Chromium is the core Internet browser, the engine around which, Google Chrome is built; with alterations for different Operating Systems.

Microsoft Edge is built around the Chromium engine. Same for Brave Browser and some others.


17 posted on 10/19/2024 7:46:16 AM PDT by linMcHlp
[ Post Reply | Private Reply | To 16 | View Replies]

To: linMcHlp

Anyone using Google’s chrome is a doofus. You get the same features by substituting the Chromium version that had all the spyware from Google ripped out.


18 posted on 10/19/2024 8:00:51 AM PDT by bobbo666
[ Post Reply | Private Reply | To 1 | View Replies]

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
General/Chat
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson