Google Chrome Vulnerabilities

 

In today’s SensCy Cyber Alert, your SensCy team recommends Google Chrome Browser users to install the new Chrome Version immediately. The new update patches 6 flaws, ensuring users are protected against the latest Google Chrome vulnerabilities.

Multiple vulnerabilities have been discovered in Google Chrome, the most severe of which could allow for arbitrary code execution. Successful exploitation of the most severe of these Google Chrome vulnerabilities could allow for arbitrary code execution in the context of the logged-on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.

Users whose accounts are configured to have fewer user rights on the system could be less impacted by these Google Chrome vulnerabilities than those who operate with administrative user rights.

The update fixes 1 critical vulnerability, tracked as CVE-2024-7532. Prompt patching is the most effective defense against Google Chrome vulnerabilities of this magnitude.

Below are the new available updates:

  • Windows and Mac: Chrome prior to 127.0.6533.99/.100
  • Linux: Chrome prior to 127.0.6533.99

Key Takeaways

  • Urgent Security Update: Google Chrome users should update immediately to address 6 new security flaws, including one critical out-of-bounds memory access issue.
  • Critical Vulnerability Patched: The update resolves CVE-2024-7532, a severe vulnerability that could allow attackers to execute arbitrary code.
  • High Risk for Administrators: Users operating with full administrative privileges face greater risks of data theft and system compromise if left unpatched.
  • Target Versions: Secure versions include Chrome 127.0.6533.99/.100 for Windows/Mac and 127.0.6533.99 for Linux.

How to check for new updates:

For new Google Chrome updates, follow these steps:

  1. On your computer, open Chrome.
  2. At the top right, click the ellipsis (…).
  3. Click Help and then About Google Chrome.
  4. Click Update Google Chrome.

Important: If your Chrome browser is up-to-date, you will see a blue check mark and the words “Chrome is up to date.”

Frequently Asked Questions (FAQ)

1. What is CVE-2024-7532?

CVE-2024-7532 is a critical security vulnerability patched in this update. It involves an “out-of-bounds memory access” issue in the PDF component of the browser, which hackers could exploit to crash the system or execute malicious code.

2. What happens if I don’t update Chrome?

Failing to update leaves your browser exposed to known exploits. If you visit a malicious website while running an outdated version, attackers could install malware, steal your passwords, or gain control of your computer without you clicking anything.

3. Why are administrative users at higher risk?

If an attacker successfully exploits a vulnerability, they gain the same rights as the current user. If you are logged in as an administrator, the attacker gains full control over the system (installing software, deleting files). If you are a standard user, the attacker’s access is limited to just your account, minimizing the damage.

4. How do I know if the update installed correctly?

After clicking “Update Google Chrome,” you must restart the browser. Go back to Help > About Google Chrome and verify that the version number matches or exceeds 127.0.6533.99. If it says “Chrome is up to date,” you are safe.

If you need additional assistance, use this Google Chrome link.