--°C
Loading...
Listen to Article
2 min read
80%

These flaws allowed hackers to gain access to all of the users' data and even execute arbitrary code by circumventing all security protections


Digital Desk: The Computer Emergency Response Team (CERT-In) of the Indian government has identified various flaws in Chrome and Mozilla products. According to CERT-In, these flaws allowed hackers to gain access to all of the users' data and even execute arbitrary code by circumventing all security protections.


CERT-In classified the vulnerabilities as 'high' risk as they affected Chrome OS versions prior to 96.0.4664.209. Google has classified the vulnerabilities as CVE-2022-1489, CVE-2022-1633, CVE-202-1636, CVE-2022-1859, CVE-2022-1867, and CVE-2022-23308. The tech behemoth identified the flaws and stated that it had been resolved. However, to stay protected from these flaws, the company advised customers to download the most recent version of Chrome OS.


CERT-In also found problems in Mozilla Firefox iOS version prior to 101, Mozilla Firefox Thunderbird version prior to 91.10, Mozilla Firefox ESR version prior to 91.10, and Mozilla Firefox version 101. Mozilla has categorised all of the vulnerabilities as 'serious.' According to the company, these flaws allowed a remote attacker to access sensitive data, bypass security limitations, execute arbitrary code, perform spoofing attacks, and cause denial-of-service (DoS) assaults on the targeted system. 


Mozilla has also issued updates on the concerned products. To protect themselves from this vulnerability, users should download Mozilla Firefox iOS 101, Mozilla Firefox Thunderbird version 91.10, Mozilla Firefox ESR version 91.10, and Mozilla Firefox version 101.


According to CERT-In, these flaws allow attackers to carry out a denial of service attack on targeted systems. A denial-of-service (DoS) attack occurs when hackers prevent users from accessing information systems, devices, or other resources. Email, websites, and online accounts are among the services that are commonly targeted by such attacks.


According to the government agency, an attacker might use these flaws to execute arbitrary code on the targeted system. "These vulnerabilities exist in Google Chrome OS due to heap buffer overflow in V8 internalisation; use after free in the Share sheet, Performance Manager, and Performance APIs; vulnerability reported in dev-libs/libxml2; insufficient validation of untrusted input in Data Transfer; and out of bounds memory access in UI Shelf," according to CERT-In.



FOLLOW US F
POPULAR
FEATURE
TRENDY
Tension Grips Doomdooma after Man Allegedly Abducts Girl using False Identity
Two Armed Dacoits Apprehended by Rupahihat Police: Pistol and Ammunition Recovered
Assam Contractor Brutally Murdered in Chennai; Bangladeshi Woman and Two Accomplices Arrested
Dispur: Auto-Rickshaw Driver Arrested for Abduction and Attempted Rape
EU Signals Strong Investment Interest in Assam Following Blue Valley Cluster Launch
Guwahati: Attempted Child Abduction Foiled as Miscreant Disguised as Beggar Targets School Student