Google Chrome users are under high risk bug says Government alert
Recently, the Indian National Security Agency, CERT-In, because of its high-risk alert to the users of popular web browser Google Chrome. This advisory is out as a response to multiple vulnerability exposures detected for Google Chrome versions V122.0.6261.11/2 and after on Windows and Mac systems. These vulnerabilities are categorized with a HIGH severity rating as information of their high level of threat to users' privacy.
Vulnerabilities Exploited by Attackers
According to the CERT-In's advisory, Google Chrome possesses a set of identified vulnerabilities that could lead to data breaches and malicious attacks on the integrity of the system. These vulnerabilities include:
1. Use-after-free in FedCM Component: This is a vulnerability, which even after use of the browser results in its memory being manipulated which may lead to unauthorized code execution.
2. Issues in V8 JavaScript Engine: Vulnerabilities regarding unauthorized memory access and inappropriate execution in the V8 JavaScript engine, which leads to code injection or browser shutdown, is a possibility for attackers.
Potential Risks and Consequences
If exploited by malicious actors, these vulnerabilities could lead to dire consequences for Google Chrome users:
1. Data Breaches: Intruders can get into a browser and get hold of the data stored there that users consider private and important, like their logins, credit card details, or personal information.
2. Malware Installation: The malware installation on users' devices may follow and the attackers will try to steal data further or even make the hacked computers tools for the criminals.
3. System Takeover: At the end, cybercriminals could operate users' systems to complete disarray or use them as a base to propagate additional attacks.
Mitigation Measures
However, Google rapidly took necessary measures including issuing security updates to tackle these security loopholes. As advised by CERT-In, users who are using Google Chrome should immediately update their installations to version 122.0.6261.11/2 or later. The user can achieve this porch by navigating to "Settings" > "About" > "Chrome" which is located in the browser.