Wednesday, April 23, 2025
HomeChromeActive Attacks Targeting Google Chrome & ownCloud Flaws: CISA Warns

Active Attacks Targeting Google Chrome & ownCloud Flaws: CISA Warns

Published on

SIEM as a Service

Follow Us on Google News

The CISA announced two known exploited vulnerabilities active attacks targeting Google Chrome & own cloud vulnerabilities in their catalog.

As the national coordinator for critical infrastructure security and resilience, CISA oversees government cybersecurity operations. 

Document
Protect Your Storage With SafeGuard

Is Your Storage & Backup Systems Fully Protected? – Watch 40-second Tour of SafeGuard

StorageGuard scans, detects, and fixes security misconfigurations and vulnerabilities across hundreds of storage and backup devices.

- Advertisement - Google News

CVE-2023-6345:

A remote attacker who had infiltrated the renderer process could have been able to carry out a sandbox escape using a malicious file thanks to an integer overflow in Skia in Google Chrome versions before 119.0.6045.199.

The severity range of this vulnerability is High. The vulnerability is currently being investigated process.

CVE-2023-49103:

This relies on a third-party GetPhpInfo.php library that provides a URL, and it reveals the configuration information of the PHP environment. The information contains the most sensitive data such as ownCloud admin password, mail server credentials, and license key. 

Furthermore, phpinfo makes many other potentially sensitive configuration details available that an attacker could use to learn more about the system. Thus, this vulnerability should still be of concern even if ownCloud is not operating in a containerized context. 

The severity range of this vulnerability is critical(10.0) and is also under the investing process.

Experience how StorageGuard eliminates the security blind spots in your storage systems by trying a 14-day free trial.

Latest articles

Hackers Exploit NFC Technology to Steal Money from ATMs and POS Terminals

In a disturbing trend, cybercriminals, predominantly from Chinese underground networks, are exploiting Near Field...

Threat Actors Leverage TAG-124 Infrastructure to Deliver Malicious Payloads

In a concerning trend for cybersecurity, multiple threat actors, including ransomware groups and state-sponsored...

Ransomware Actors Ramp Up Attacks Organizations with Emerging Extortion Trends

Unit 42’s 2025 Global Incident Response Report, ransomware actors are intensifying their cyberattacks, with...

New SMS Phishing Attack Weaponizes Google AMP Links to Evade Detection

Group-IB’s High-Tech Crime Trends Report 2025 reveals a sharp 22% surge in phishing websites,...

Resilience at Scale

Why Application Security is Non-Negotiable

The resilience of your digital infrastructure directly impacts your ability to scale. And yet, application security remains a critical weak link for most organizations.

Application Security is no longer just a defensive play—it’s the cornerstone of cyber resilience and sustainable growth. In this webinar, Karthik Krishnamoorthy (CTO of Indusface) and Phani Deepak Akella (VP of Marketing – Indusface), will share how AI-powered application security can help organizations build resilience by

Discussion points


Protecting at internet scale using AI and behavioral-based DDoS & bot mitigation.
Autonomously discovering external assets and remediating vulnerabilities within 72 hours, enabling secure, confident scaling.
Ensuring 100% application availability through platforms architected for failure resilience.
Eliminating silos with real-time correlation between attack surface and active threats for rapid, accurate mitigation

More like this

Hackers Exploit NFC Technology to Steal Money from ATMs and POS Terminals

In a disturbing trend, cybercriminals, predominantly from Chinese underground networks, are exploiting Near Field...

Threat Actors Leverage TAG-124 Infrastructure to Deliver Malicious Payloads

In a concerning trend for cybersecurity, multiple threat actors, including ransomware groups and state-sponsored...

Ransomware Actors Ramp Up Attacks Organizations with Emerging Extortion Trends

Unit 42’s 2025 Global Incident Response Report, ransomware actors are intensifying their cyberattacks, with...