Home » TRENDING NEWS » Centre Issues Warning About Multiple Bugs in Google Chrome for Desktop Users

Centre Issues Warning About Multiple Bugs in Google Chrome for Desktop Users

The Indian Computer Emergency Response Team (CERT-In) has issued a warning to users about several vulnerabilities in Google Chrome for desktops that could allow hackers to gain access to their computers.

The multiple vulnerabilities, according to an IT Ministry advisory, could allow a remote attacker to execute arbitrary code and bypass security restrictions on the targeted system.

These vulnerabilities exist in Google Chrome due to use after free in FedCM, SwiftShader, ANGLE, Blink, Sign-In Flow, Chrome OS Shell; heap buffer overflow in Downloads, insufficient validation of untrusted input in Intents, insufficient policy enforcement in Cookies, and inappropriate implementation in Extensions API, according to the cyber agency.

A hacker could take advantage of these flaws by sending specially crafted requests to the targeted system.

According to CERT-In, successful exploitation of these vulnerabilities could allow a remote attacker to execute arbitrary code and bypass security restrictions on the targeted system. In the wild, the vulnerability (CVE-2022-2856) is being exploited. Users are advised to apply patches as soon as possible. CERT-In also issued a warning about bugs in Apple’s iOS, iPadOS, and macOS, stating that a remote attacker could exploit this vulnerability by luring a victim into opening a specially crafted file.

It also discovered a number of vulnerabilities in Cisco products that could allow an attacker to execute arbitrary code, disclose sensitive information, or launch a cross-site scripting attack on a vulnerable system. Previously, the nation’s top cyber agency issued warnings about bugs in Cisco products.

Check Also

Low-code platform provider Pegasystems has integrated its Pega Process AI technology into Pega Smart Dispute, a move set to aid retail banks in optimizing their chargeback processes.

Pegasystems Unveils AI-Infused Solution to Expedite Retail Bank Chargebacks

Low-code platform provider Pegasystems has integrated its Pega Process AI technology into Pega Smart Dispute, …

Do NOT follow this link or you will be banned from the site!