Once again Google has fixed another Zero-day vulnerability in the Chrome browser, and this is the second vulnerability that has been recently fixed by Google.
However, Google has dispatched the new version “89.0.4389.90” on Friday for all the major platforms (Windows, Mac, and Linux), which is expected to come out in a few days/weeks to all users.
As per the record, this new update includes a total of five security fixes, and the most significant flaw among all is being amended by Google. Here are the flaws that were fixed by the external researchers:-
This flaw affects usage after free vulnerability in its Blink rendering engine, that’s why Google has labeled the bug as CVE-2021-21193.
It is not yet clear that which researchers have detected this vulnerability, and that’s why it’s named under Google. Google has described the vulnerability and proclaimed that it is used as a free bug in Blink.
Moreover, it is an open-source browser rendering engine generated by the Chromium project along with different participation from Google, Facebook, Microsoft, and many others.
The analyst of Google affirmed that every Chrome user should spend more time installing the security update that is operating out over the subsequent days so that it will prevent further exploitation.
Google has listed all the possible areas in which all the given weaknesses could appear, and here they are mentioned below:-
There are also some common consequences, and here they are:-
Google has also patched the third Chrome Zero-day flaw this year, and the bug was named CVE-2021-21166. It was exploited in the wild and was being portrayed as an “Object lifecycle issue in audio” the experts have addressed the flaw along with the release of Chrome 89.0.4389.72.
While on February 4, the company finally resolved another actively-exploited heap buffer overflow flaw in its V8 JavaScript rendering engine.
Not only this but in the case of this vulnerability, Chrome users can simply update to the latest version by going to Settings > Help > About Google Chrome to decrease the risk that is blended with the flaw.
You can follow us on Linkedin, Twitter, Facebook for daily Cybersecurity, and hacking news updates.
Sonatype, the company behind the popular Nexus Repository Manager, has issued security advisories addressing two…
Cybersecurity researchers have detected the active exploitation of a zero-day vulnerability in GeoVision devices, which…
A critical security flaw has been uncovered in certain TP-Link routers, potentially allowing malicious actors…
SilkSpecter, a Chinese financially motivated threat actor, launched a sophisticated phishing campaign targeting e-commerce shoppers…
The research revealed how threat actors exploit SEO poisoning to redirect unsuspecting users to malicious…
Black Basta, a prominent ransomware group, has rapidly gained notoriety since its emergence in 2022…