Google has released Chrome 45 to address 29 security flaws affecting Windows, Mac, and Linux platforms. According to Google advisory, Six issues are rated as CRITICAL allowing remote code execution. These high-severity issues addressed cross-origin bypass flaws in DOM, covered in CVE-2015-1291 and CVE-2015-1293, where as a cross-origin bypass issue occurs in Service Worker that is covered in CVE-2015-1292. Besides this, multiple use-after-free flaws in Skia (CVE-2015-1294) and Printing (CVE-2015-1295), and a character spoofing bug in the Omnibox address bar (CVE-2015-1296). The latest version also patched medium severity vulnerabilities in WebRequests, extensions and in the Blink web browser engine. Google credits security researchers Mariusz Mlynski, Rob Wu, Alexander Kashev, and experts using the online monikers taro.suzuki.dev, cgvwzq, cloudfuzzer, and zcorpan for finding vulnerabilities in the browser. So far, company has given rewards of $40,500 through bug bounty program. Morever, Google has decided to stop running Flash Ads due to various flaws found in Adobe Flash from time to time. Google is automatically converting most of the Flash ads uploaded to AdWords to HTML5, otherwise it can be done manually using a tool provided by the company. <more>
Monday, September 7, 2015
Bugzilla hack eXposes Firefox 0-day flaw
Mozilla confirmed about Bugzilla breached by an attacker who was able to get access to sensitive information about zero-day flaws in Firefox. According to Mozilla, the intruder was able to breach a high-level user's account who had access to Bugzilla that contains information of non-public zero-day security flaws. Mozilla said attacker took control of the account since September 2013 and accessed approximately 185 vulnerabilities that were non-public, where 53 vulnerabilities considered CRITICAL flaws. However, company claims 43 of the severe flaws had already been patched, but 10 unpatched security flaws are still in the hands of intruder which pose a huge security risk for Firefox users. <more>
Wednesday, August 5, 2015
Not Again !! Another bug puts Android phone @ risk
Earlier it was Zimperium that informed about the Stagefright flaw affecting nearly 950 million (95%) smartphone across the globe, and now its Trend Micro turns to come up with another security flaw in the Android mediaservice which can cause your smartphone to become unresponsive. As compare to Stagefright bug, this new vulnerability affects Android versions 4.3 and above. So statistically 56.8% users are affected to this flaw. According to security researcher from Trend Micro, attackers can exploit the vulnerability using a malicious app installed and running on the user's device, or by accessing a URL where a malformed media file is hosted. For demonstration purpose, researcher choked the mediaserver service using a malformed MKV file. The issue exists in the way mediaserver service reads data from a Matroska media container, which is used with the .mkv extension. <more>
Subscribe to:
Posts (Atom)