Connect with us

Internet

Google Confirms Serious Chrome Security Problem – Here’s How To Fix It

Published

on

Google Chrome’s security lead and engineering director, Justin Schuh, has warned that users of the most popular web browser should update “like right this minute.” Why the urgency? Simply put, there is a zero-day vulnerability for Chrome that the Google Threat Analysis Group has determined is being actively exploited in the wild. What does that all mean? Well, a vulnerability is just a bug or flaw in the code and while they all need to be fixed, not all of them either can be or are being exploited. A zero-day vulnerability is one that threat actors have managed to create an exploit for, a way of doing bad things to your device or data, before the good guys even knew the vulnerability existed. In other words they have zero days in which to issue a fix. The bad news for users of Google Chrome is that this particular zero-day vulnerability, CVE-2019-5786, is already being exploited by the bad guys. Which is why it’s so important to make sure your browser has been updated to the latest patched version that fixes the vulnerability.

The problem explained

Although information regarding CVE-2019-5786 remains scarce currently, Satnam Narang, a senior research engineer at Tenable, says it is a “Use-After-Free (UAF) vulnerability in FileReader, an application programming interface (API) included in browsers to allow web applications to read the contents of files stored on a user’s computer.” Some further digging by Catalin Cimpanu over at ZDNet suggests that there are malicious PDF files in the wild that are being used to exploit this vulnerability. “The PDF documents would contact a remote domain with information on the users’ device –such as IP address, OS version, Chrome version, and the path of the PDF file on the user’s computer” Cimpanu says. These could just be used for tracking purposes, but there is also the potential for more malicious behavior. The ‘use-after-free’ vulnerability is a memory corruption flaw that carries the risk of escalated privileges on a machine where a threat actor has modified data in memory through exploiting it. That’s why Google has issued the urgent update warning, as the potential is there for exploits to be crafted that could enable an attacker to remotely run arbitrary code (a remote code execution attack) whilst escaping the browser’s built-in sandbox protection.

What to do next

Luckily this is an easy problem to fix, just make sure you do it as soon as you’ve finished reading this! First, head over to the drop-down menu in Chrome (you’ll find it at the far right of the toolbar – click on the three stacked dots) and select Help|About Google Chrome. You could also type chrome://settings/help in the address bar if you prefer, which takes you to the same dialog box. This will tell you if you have the current version running or if there is an update available. To be safe from this zero-day exploit, make sure that it says you are running version 72.0.3626.121 (Official Build). If not, then Chrome should go and fetch the latest version and update your browser for you automatically.

Continue Reading
Advertisement
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Internet

GOOGLE OFFICIALLY ANNOUNCES ANDROID 11 FOR ANDROID TV

Published

on

By

A few weeks ago, Google officially released its latest system, Android 11 for smartphones. Today, the company announced that Android 11 will now be available for Android TVs. However, the Android 11 for TV is not a direct copy of Android 11 for smartphones. There are some features that are exclusive to the large screen. According to Google, it will partner with multiple OEMs and Android 11 on TV will be available in a few months. However, those who already have the ADT-3 Developer Kit can get the update today.

Android tv mini box IFA

This system for Android TVs will retain most of the basic features of the Android 11 for smartphones. This system will come with better memory management and one-time permissions for secure workability. Google also did more work on privacy features to reduce the system’s vulnerability.

In addition, the Android 11 for Android TVs will come with an “Auto Low Latency Mode and low latency media decoding”. This system will also bring a new Tuner Framework with updated Media CAS support. Furthermore, this system will support gamepads, a feature that will be important for Stadia on the TV. Developers of Android TV apps can seamlessly test their apps with Google’s “test harness mode for Android TV”.

According to Google, the Android 11 system allows better control over TV functions. The company said the “…new framework functionality for managing System LEDs and physical microphone mute buttons also facilitate integrations for far-field microphone enabled devices”.

Source: https://www.gizchina.com/2020/09/22/google-officially-announces-android-11-for-android-tv/

Continue Reading

Internet

Google Chrome prepares new tab groups feature that creates groups automatically

Published

on

By

Months after announcing it, Google finally rolled out tab groups widely in the past couple of weeks. Now, an improvement could be coming to Chrome’s tab group feature — the ability to recreate them automatically.

In the latest Chrome Canary release, a new flag is present that describes a feature Google is working on. That flag, titled “tab groups auto create,” is one that has had us scratching our heads since it popped onto our radar earlier this week.

Google’s description, too, unfortunately doesn’t help matters. the company simply explains that the feature “automatically creates groups for users, if tab groups are enabled” in Chrome. What does that mean? We’re not entirely sure, but there are a few possibilities!

For one, Google might be able to remember tab groups from a previous session and drop them into a group when opened. Alternatively, Google could intelligently create groups based on similar types of tabs. At this point, it’s all up in the air. We can say pretty confidently, however, that this feature is not live in the latest Canary release.

Source: https://9to5google.com/2020/09/17/google-chrome-tab-groups-automatic-flag/

Continue Reading

Internet

Facebook Is Apparently Adding Instagram Stories to Its Key Application

Published

on

By

Facebook has built it no key that it would like to entwine Instagram into its principal blue app as a great deal as possible (to some Instagram users’ chagrin.) Its most recent experiment evidently requires placing Instagram stories right on Facebook.

In accordance to a report in the Verge, some Facebook customers have lately started looking at Instagram stories in their Fb story feeds. A Fb representative apparently verified the news to Matt Navarra, a social media marketplace commentator and advisor, and stated that it was a restricted examination. The representative added that Facebook would be listening to feedback from its group on the prospective new characteristic.

In a screenshot posted by a Twitter consumer and Navarra on Friday, Fb seemingly points out that not just anyone can view an Instagram story on Facebook. In get to do so, consumers have to website link their Instagram accounts to Facebook and have this viewing placing turned on. Fb states that men and women who don’t abide by a user on Instagram will not be ready to see that user’s tales.

Fb also purportedly pressured that even however tales will be in two sites, users’ overall practical experience would not improve. That is mainly because people will nevertheless essentially be sharing their tales with the similar persons on Facebook and Instagram. In addition, Instagram stories on Facebook (which will have a pink and orange circle) will surface with a user’s Instagram take care of. And even though the tales will be seen on Fb, end users will see all tale sights and replies on Instagram.

In new many years, Facebook has labored to convey all of its popular apps, which involve WhatsApp and Instagram, nearer with each other. Very last thirty day period, Facebook released a new exam working experience on Instagram messaging for some users. The new experience up-to-date the look of Instagram immediate messages and promoted the likelihood of chatting with individuals who use Fb.

Who knows, possibly in the foreseeable future we won’t have an application named Instagram or Fb. We’ll just have a person giant purple and blue app, owned by Facebook, that does almost everything.

Source: https://poptimesuk.com/facebook-is-apparently-adding-instagram-stories-to-its-key-application/175242/

Continue Reading
Advertisement

Trending

Copyright © 2020 Inventrium Magazine

%d bloggers like this: