Wednesday, June 19, 2024

Chrome 72 Released with 58 Security fixes, Removes HPKP and Deprecate TLS 1.0 and 1.1

Google released Chrome 72 stable version for Windows, Mac, and Linux. The Chrome 72.0.3626.81 comes with the fix for 58 security bugs and includes a number of improvements.

The release includes some major updates that includes Deprecate of the TLS 1.0 and 1.1 protocols and HTTP-Based Public Key Pinning.

Depreciation of TLS 1.0, TLS 1.1 and HPKP

Starting from Google Chrome 72, the chrome has taken the first step in removing the support for TLS 1.0 and TLS 1.1 protocols. During the depreciation period if any sites using TLS 1.0 and 1.1 shows a warning in browser devtools.

After the depreciation period, in 2020, if any sites using TLS 1.0 and 1.1 will fail to connect with the and the website administrators need to upgraded with TLS 1.2.

HPKP support was removed, it is a security feature that prevents the misissuance of the certificate but the adoption rate is very low.

Chrome to remove the support for rendering resources from FTP servers and instead allows users to download them directly.

Popups during page unload are blocked, “the popup blocker already prohibited this, but now it is prohibited whether or not the popup blocker is enabled.”

Chrome Web Authentication API which adds support for communicating with external devices over BLE, including a UI to guide users in pairing and using their devices for two-factor authentication.

Chrome 72 comes with a fix for 58 security bugs that identified from internal audits, fuzzing and other initiatives such as AddressSanitizer, MemorySanitizer, UndefinedBehaviorSanitizer, Control Flow Integrity, libFuzzer, or AFL.

Firefox 65.0 released few hours before the Chrome update, the Firefox updates fixes several security vulnerabilities along with various new futures including video streaming experience, updated language preference etc.

You can follow us on LinkedinTwitterFacebook for daily Cybersecurity updates also you can take the Best Cybersecurity courses online to keep your self-updated.

Website

Latest articles

Singapore Police Arrested Two Individuals Involved in Hacking Android Devices

The Singapore Police Force (SPF) has arrested two men, aged 26 and 47, for...

CISA Conducts First-Ever Tabletop Exercise Focused on AI Cyber Incident Response

On June 13, 2024, the Cybersecurity and Infrastructure Security Agency (CISA) made history by...

Europol Taken Down 13 Websites Linked to Terrorist Operations

Europol and law enforcement agencies from ten countries have taken down 13 websites linked...

New ARM ‘TIKTAG’ Attack Impacts Google Chrome, Linux Systems

Memory corruption lets attackers hijack control flow, execute code, elevate privileges, and leak data.ARM's...

Operation Celestial Force Employing Android And Windows Malware To Attack Indian Users

A Pakistani threat actor group, Cosmic Leopard, has been conducting a multi-year cyber espionage...

Hunt3r Kill3rs Group claims they Infiltrated Schneider Electric Systems in Germany

The notorious cybercriminal group Hunt3r Kill3rs has claimed responsibility for infiltrating Schneider Electric's systems...

Hackers Employing New Techniques To Attack Docker API

Attackers behind Spinning YARN launched a new cryptojacking campaign targeting publicly exposed Docker Engine...
Guru baran
Guru baranhttps://gbhackers.com
Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

Free Webinar

API Vulnerability Scanning

71% of the internet traffic comes from APIs so APIs have become soft targets for hackers.Securing APIs is a simple workflow provided you find API specific vulnerabilities and protect them.In the upcoming webinar, join Vivek Gopalan, VP of Products at Indusface as he takes you through the fundamentals of API vulnerability scanning..
Key takeaways include:

  • Scan API endpoints for OWASP API Top 10 vulnerabilities
  • Perform API penetration testing for business logic vulnerabilities
  • Prioritize the most critical vulnerabilities with AcuRisQ
  • Workflow automation for this entire process

Related Articles