Google has issued its third urgent update for Google Chrome on Thursday, to patch the zero-day vulnerability in the highly-used desktop web browser. The Stable Channel Update introduced version 100.0.4898.127, on macOS, Windows, and Linux. This new update comes with a pair of security fixes, including a "type confusion" vulnerability designated as CVE-2022-1364. Reportedly, the bug is a Type Confusion in V8 vulnerability, which is Google’s open source high-performance JavaScript and WebAssembly engine. Google in one of its blog posts mentioned that the bug is already being exploited in the wild and is actively being used by attackers. Hence, Google has to issue the third emergency update for Google Chrome this year.
This is the type of Google Chrome bug is similar to one that Google patched on March 26. It can cause a browser to crash or trigger an error, which has the potential to allow arbitrary code to be executed.Google wrote, “With a type-confusion flaw, a program will allocate a resource like a pointer or object using one type but later will access the resource using another, incompatible type. In some languages, like C and C++, the vulnerability can result in out-of-bounds memory access.”
According to the Center for internet security, the attackers can even view, change or delete data depending on the privileges associated with the application. If this application has been configured to have fewer user rights on the system, the vulnerability could have less impact on the system.
However, with the new Google Chrome update rolling out the bug will likely get fixed. Do note that the new version of Google Chrome can be updated automatically for the user, but macOS users will have to do it manually. They will be
Read more on tech.hindustantimes.com