Google releases update to fix another zero-day flaw in Chrome browser

Google released an updated version of the Chrome browser on Tuesday that included seven security fixes, including a patch for a zero-day flaw that hackers may have actively been exploiting, Google said. Google has been dealing with several serious flaws in recent days. The update details four other vulnerabilities and fixes Google had to roll out this week. Google previously fixed another zero-day flaw on April 12, as well. If the zero-day flaw, classified as CVE-2021-21224, was exploited in concert with another vulnerability, hackers would have been able to execute arbitrary code on victims’ systems. VerSprite Inc’s Jose Martinez reported the vulnerability, which Google describes as a Type Confusion in V8, several days ago, linking it to a proof-of-concept exploit that took advantage of the bug. That proof-of-concept code was available on Twitter, and thus accessible to the public, though there were no reports of attackers leveraging the bug in […]

The post Google releases update to fix another zero-day flaw in Chrome browser appeared first on CyberScoop.

Continue reading Google releases update to fix another zero-day flaw in Chrome browser

Chrome to Enforce HTTPS Web Protocol (Like It or Not)

What a difference an ‘s’ makes. This seemingly unimportant change could have a big—if unseen—impact.
The post Chrome to Enforce HTTPS Web Protocol (Like It or Not) appeared first on Security Boulevard.
Continue reading Chrome to Enforce HTTPS Web Protocol (Like It or Not)

Google speeds up its release cycle for Chrome

Google today announced that its Chrome browser is moving to a faster release cycle by shipping a new milestone every four weeks instead of the current six-week cycle (with a bi-weekly security patch). That’s one way to hasten the singularity, I guess, but it’s worth noting that Mozilla also moved to a four-week cycle for […] Continue reading Google speeds up its release cycle for Chrome