The Indian Computer Emergency Response Team (CERT-In) has raised a high-severity warning regarding vulnerabilities present in Google Chrome OS, urging users to update their browsers immediately. Released on February 8, 2024, under the designation CIVN-2024-0031, the security note highlights significant risks associated with Google Chrome OS versions preceding 114.0.5735.350 (Platform Version: 15437.90.0) on the LTS channel. Govt wants you to download the latest Google Chrome update as that will remove all current vulnerabilities that are there.
CERT-In identifies these vulnerabilities as exploitable by remote attackers to execute arbitrary code, gain elevated privileges, bypass security restrictions, or cause denial of service conditions on affected systems. The vulnerabilities primarily stem from two sources: a "use after free" flaw in the Side Panel Search feature and inadequate data validation in extensions, both of which can be leveraged by attackers to compromise system integrity.
Remote attackers can exploit these vulnerabilities by enticing users to visit specially crafted web pages, triggering the identified vulnerabilities upon access. To mitigate these risksHT, CERT-In strongly recommends updating Google Chrome OS to version 114.0.5735.350 or later, as these updates contain patches addressing the identified vulnerabilities.
Additionally, users are advised to exercise caution while browsing the internet, especially when encountering unfamiliar or suspicious websites, and to avoid interacting with links from untrusted sources or unsolicited emails and messages. Implementing security best practices such as using reputable antivirus software, regularly updating software and applications, and enabling firewalls can further enhance defense mechanisms against potential threats.
In parallel, CERT-In is conducting a "Cyber Swachhta Fortnight" from February 1 to 15, 2024, aimed at securing cyberspace from botnets, which pose a threat to end user systems. As part of this
Read more on tech.hindustantimes.com