小程序
传感搜
传感圈

Google Chrome Hit With Zero Day Bug, Again. Here's Why You Should Update Your App

2022-08-20
关注

Google Chrome is asking users to update their browsers after the Internet giant revealed hackers are privy to a "zero-day" bug that could give attackers access to your private information.

A zero-day bug is a security vulnerability known to hackers before the vendor is aware, and it's already being used by hackers.

While Google says it has resolved 11 security vulnerabilities ranging from medium to critical impact in its latest update, one may still be known to hackers.

"Google is aware that an exploit for CVE-2022-2856 exists in the wild," according to an August 16 press release.

CVE-2022-2856 marks the fifth zero-day that Google has experienced in 2022, per Forbes.

Since zero-day hacks may be unbeknownst to the vendor, there is no patch for the vulnerability.

Google has yet to share specific details about the zero-day bug but said in their press release that "access to bug details and links may be kept restricted until a majority of users are updated with a fix."

However, they do reveal that it was reported by hackers from the Google Threat Analysis Group on July 9, and described the issue as "Insufficient validation of untrusted input in Intents." Here, "intents" is how Chrome processes user input, meaning a possible input could be interfering with Google's code.

The day before reporting the vulnerability, Google Chrome shared two tweets about zero-day bugs.

What are zero-day exploits — and how does #Chrome protect you from them?

ICYMI: Watch as Security Sheriff Adrian Taylor explains why these bugs are the highest priority for Chrome's security team → https://t.co/p3QNGQQ7Cz pic.twitter.com/JjUbdW3Pa4

— Chrome (@googlechrome) August 15, 2022

In the video, "Security Sheriff" Adrian Taylor says "all software can have bugs, even that built to the highest engineering standards like Chrome." Explaining that "malicious websites" may use bugs to steal your information, he said, "We address any security bug with great urgency, but with even more urgency for zero-day bugs."

As Chrome gains more visibility into how attackers use zero-day bugs, we're becoming more sophisticated in how we discover and fix vulnerabilities. Learn how we're adding even more layers of defense that make it difficult for attackers to bypass: https://t.co/s61p1Sa1kS

— Chrome (@googlechrome) August 15, 2022

To best protect yourself, it's advised to update your Google Chrome browser and app. While it should automatically update, users can check by going to About Google Chrome in your browser menu, which will force check for any possible updates.

参考译文
谷歌Chrome与零日Bug,再次击中。以下是你应该更新应用程序的原因
Chrome浏览器要求用户更新他们的浏览器,此前这家互联网巨头透露黑客们对一个零日"漏洞,可能使攻击者访问您的私人信息。零日漏洞是黑客在供应商意识到之前就知道的安全漏洞,而且黑客已经在使用它。虽然谷歌表示在其最新的更新中已经解决了11个安全漏洞,从中等影响到严重影响,但其中一个漏洞仍可能为黑客所知。谷歌知道存在一个针对CVE-2022-2856的漏洞,"根据8月16日的新闻稿。据《福布斯》报道,CVE-2022-2856标志着谷歌在2022年经历的第5个零日。由于供应商可能不知道零日攻击,因此没有针对该漏洞的补丁。谷歌尚未分享关于这个零日漏洞的具体细节,但在他们的新闻稿中表示,在大多数用户更新修复之前,对漏洞细节和链接的访问可能会受到限制。然而,他们确实透露,7月9日谷歌威胁分析小组的黑客报告了这个问题,并将该问题描述为Intents中不可信输入的验证不足。在这里,& # 34;意图# 34;是Chrome如何处理用户输入,这意味着可能的输入可能会干扰Google's代码。在报告漏洞的前一天,谷歌Chrome分享了两条关于零日漏洞的推文。什么是零日漏洞? #Chrome如何保护你免受它们的侵害?ICYMI:观看安全警长阿德里安·泰勒解释为什么这些漏洞是Chrome's安全团队的最高优先级→https://t.co/p3QNGQQ7Cz pic.twitter.com/JjUbdW3Pa4In视频,"阿德里安泰勒说,所有的软件都可能有bug,即使是建立在最高的工程标准,如Chrome。"恶意网站"他说,可能会利用漏洞来窃取你的信息,我们非常迫切地解决任何安全漏洞,但对零日漏洞的紧迫性更大。随着Chrome越来越清楚地了解攻击者如何使用零日漏洞,我们在发现和修复漏洞方面变得越来越老练。了解我们如何添加更多的防御层,使攻击者难以绕过:https://t.co/s61p1Sa1kSTo最好的保护自己,it's建议更新您的谷歌Chrome浏览器和应用程序。虽然它应该自动更新,用户可以检查通过去约谷歌Chrome在你的浏览器菜单,这将强制检查任何可能的更新。
您觉得本篇内容如何
评分

评论

您需要登录才可以回复|注册

提交评论

提取码
复制提取码
点击跳转至百度网盘