Chrome Google Chrome



Google has released Chrome 90.0.4430.85 to address an actively exploited zero-day and four other high severity security vulnerabilities impacting today's most popular web browser.

  1. Chrome Google Chromecast
  2. Chrome Google Chrome

The version released on April 20th, 2021, to the Stable desktop channel for Windows, Mac, and Linux users will be rolling out to all users over the coming weeks.

  1. Google Chrome is a fast, free web browser. Before you download, you can check if Chrome supports your operating system and you have all the other system requirements. Install Chrome on Windows.
  2. Discover great apps, games, extensions and themes for Google Chrome.

'Google is aware of reports that exploits for CVE-2021-21224 exist in the wild,' the company's announcement reads.

PoC dropped on Twitter, zero-day fixed one week later

1 day ago  Indeed, he thinks Google Chrome’s change will inspire a further shift for advertisers to think about creating more diverse adverts that speak to underserved audiences.

Google did not share any details on the zero-day besides describing it as a 'Type Confusion in V8' and saying that it was reported by VerSprite Inc's Jose Martinez.

However, Martinez linked it to a proof-of-concept (PoC) exploit publicly shared on Twitter one week ago after his initial Chrome Vulnerability Reward Program report from April 5th.

Chrome Google Chromecast

This remote code execution vulnerability cannot be exploited by attackers to escape Chromium's sandbox security feature (a security feature designed to block exploits from accessing files or executing code on host computers).

However, it can easily be chained with another security bug that can allow the exploit to escape the sandbox and execute arbitrary code on the targeted users' systems.

The zero-day PoC for CVE-2021-21224 was dropped on Twitter one day after Google released Chrome 89.0.4389.128 to fix another zero-day bug with a PoC exploit publicly shared two days earlier.

hi haha right, I'm the original reporter.
Timeline:
5th April: I've submitted my bug to Google Chrome VRP report
12th April: I've submitted my RCE 0day exploit
12th April: Google patched v8 engine, but also made regress/unittest public
14th April: people viralized 1day exploit

— JosexD j0s3 tr0y4 (@JosexDDD) April 20, 2021

No details on zero-day attacks in the wild

Install google chrome on laptop

Although Google says that it is aware CVE-2020-16009 active exploitation, the company did not provide any info on the threat actors behind these attacks.

'Access to bug details and links may be kept restricted until a majority of users are updated with a fix,' Google said.

'We will also retain restrictions if the bug exists in a third party library that other projects similarly depend on, but haven't yet fixed.'

Google fixed three other high severity vulnerabilities in Chrome 90.0.4430.85:

  • CVE-2021-21222: Heap buffer overflow in V8. Reported by Guang Gong of Alpha Lab, Qihoo 360 on 2021-03-30
  • CVE-2021-21223: Integer overflow in Mojo. Reported by Guang Gong of Alpha Lab, Qihoo 360 on 2021-04-02
  • CVE-2021-21225: Out of bounds memory access in V8. Reported by Brendon Tiszka (@btiszka) supporting the EFF on 2021-04-05
  • CVE-2021-21226: Use after free in navigation. Reported by Brendon Tiszka (@btiszka) supporting the EFF on 2021-04

Related Articles:

The web browser is arguably the most important piece of software on your computer. You spend much of your time online inside a browser: when you search, chat, email, shop, bank, read the news, and watch videos online, you often do all this using a browser.

Google Chrome is a browser that combines a minimal design with sophisticated technology to make the web faster, safer, and easier. Use one box for everything--type in the address bar and get suggestions for both search and Web pages. Thumbnails of your top sites let you access your favorite pages instantly with lightning speed from any new tab. Desktop shortcuts allow you to launch your favorite Web apps straight from your desktop. Chrome has many useful features built in, including automatic full-page translation and access to thousands of apps, extensions, and themes from the Chrome Web Store.

Chrome Google Chrome

Google Chrome is one of the best solutions for Internet browsing giving you high level of security, speed and great features.

Important to know! The offline installer links do not include the automatic update feature.

Download web installer: Google Chrome Web 32-bit | Google Chrome 64-bit | Freeware
Download: Google Chrome Offline Installer 32-bit | 71.0 MB
Download: Google Chrome Offline Installer 64-bit | 73.3 MB
Download: Google Chrome MSI Installers for Windows (automatic update)
View: Chrome Website | v90.0.4430.85 Release Notes

Chrome Google Chrome

Get alerted to all of our Software updates on Twitter at @NeowinSoftware