Eleven severe vulnerabilities have been found in Chromium, including multiple Type Confusion bugs in V8, use-after-frees in Cast, Blink Task Scheduling and WebRTC, a heap buffer overflow in Visuals, out-of-bounds read and write in WebGL, out-of-bounds memory access in ANGLE, and insufficient data validation and inappropriate implementation in Extensions. These bugs have received a National Vulnerability Database severity rating of “High” due to their ease of exploitation and the significant threat they pose to impacted systems' confidentiality, integrity, and availability. . These issues have allowed a remote attacker to potentially exploit heap corruption and perform arbitrary read/write via a crafted HTML page. They also enabled an attacker who convinced a user to install a malicious extension to inject scripts or HTML into a privileged page via a crafted Chrome Extension. Important updates have been released for Chromium that fix these dangerous flaws. We urge all impacted users to apply the updates issued by Debian , Fedora and openSUSE to protect against potential security threats. To stay on top of essential updates released by the open-source programs and applications you use, register as a LinuxSecurity user , subscribe to our Linux Advisory Watch newsletter, and customize your advisories for your distro(s). This will enable you to stay up-to-date on the latest, most significant issues impacting the security of your systems. Follow @LS_Advisories on Twitter for real-time updates on advisories for your distro(s) . . Critical vulnerabilities in Chromium jeopardize platforms to distant attacks and memory corruption. Ensure updates are applied to safeguard against risks.. Chromium Flaws, High Severity Advisory, Remote Exploits, Security Update. . Brittany Day
Get the latest Linux and open source security news straight to your inbox.