Tuesday, April 15, 2025
HomeChromeActive Attacks Targeting Google Chrome & ownCloud Flaws: CISA Warns

Active Attacks Targeting Google Chrome & ownCloud Flaws: CISA Warns

Published on

SIEM as a Service

Follow Us on Google News

The CISA announced two known exploited vulnerabilities active attacks targeting Google Chrome & own cloud vulnerabilities in their catalog.

As the national coordinator for critical infrastructure security and resilience, CISA oversees government cybersecurity operations. 

Document
Protect Your Storage With SafeGuard

Is Your Storage & Backup Systems Fully Protected? – Watch 40-second Tour of SafeGuard

StorageGuard scans, detects, and fixes security misconfigurations and vulnerabilities across hundreds of storage and backup devices.

- Advertisement - Google News

CVE-2023-6345:

A remote attacker who had infiltrated the renderer process could have been able to carry out a sandbox escape using a malicious file thanks to an integer overflow in Skia in Google Chrome versions before 119.0.6045.199.

The severity range of this vulnerability is High. The vulnerability is currently being investigated process.

CVE-2023-49103:

This relies on a third-party GetPhpInfo.php library that provides a URL, and it reveals the configuration information of the PHP environment. The information contains the most sensitive data such as ownCloud admin password, mail server credentials, and license key. 

Furthermore, phpinfo makes many other potentially sensitive configuration details available that an attacker could use to learn more about the system. Thus, this vulnerability should still be of concern even if ownCloud is not operating in a containerized context. 

The severity range of this vulnerability is critical(10.0) and is also under the investing process.

Experience how StorageGuard eliminates the security blind spots in your storage systems by trying a 14-day free trial.

Latest articles

Microsoft Teams File Sharing Unavailable Due to Unexpected Outage

Microsoft Teams users across the globe are experiencing significant disruptions in file-sharing capabilities due...

Cloud Misconfigurations – A Leading Cause of Data Breaches

Cloud computing has transformed the way organizations operate, offering unprecedented scalability, flexibility, and cost...

Security Awareness Metrics That Matter to the CISO

Security awareness has become a critical component of organizational defense strategies, particularly as companies...

New ‘Waiting Thread Hijacking’ Malware Technique Evades Modern Security Measures

Security researchers have unveiled a new malware process injection technique dubbed "Waiting Thread Hijacking"...

Resilience at Scale

Why Application Security is Non-Negotiable

The resilience of your digital infrastructure directly impacts your ability to scale. And yet, application security remains a critical weak link for most organizations.

Application Security is no longer just a defensive play—it’s the cornerstone of cyber resilience and sustainable growth. In this webinar, Karthik Krishnamoorthy (CTO of Indusface) and Phani Deepak Akella (VP of Marketing – Indusface), will share how AI-powered application security can help organizations build resilience by

Discussion points


Protecting at internet scale using AI and behavioral-based DDoS & bot mitigation.
Autonomously discovering external assets and remediating vulnerabilities within 72 hours, enabling secure, confident scaling.
Ensuring 100% application availability through platforms architected for failure resilience.
Eliminating silos with real-time correlation between attack surface and active threats for rapid, accurate mitigation

More like this

Microsoft Teams File Sharing Unavailable Due to Unexpected Outage

Microsoft Teams users across the globe are experiencing significant disruptions in file-sharing capabilities due...

Cloud Misconfigurations – A Leading Cause of Data Breaches

Cloud computing has transformed the way organizations operate, offering unprecedented scalability, flexibility, and cost...

Security Awareness Metrics That Matter to the CISO

Security awareness has become a critical component of organizational defense strategies, particularly as companies...