Two serious zero-day vulnerabilities have been fixed in the emergency patch released yesterday by Google, and one of them has been exploited by hackers. The Chrome Security Team said both vulnerabilities are in a use-after-free form that allows hackers to execute arbitrary code on vulnerable devices. One of the vulnerabilities exists in the audio component of the browser, while the other exists in the PDFium library. The three major platform versions, Windows, macOS and GNU/Linux are affected.
[$7500] High CVE-2019-13721: Use-after-free in PDFium. Reported by banananapenguin on 2019-10-12[$TBD] High CVE-2019-13720: Use-after-free in audio. Reported by Anton Ivanov and Alexey Kulaev at Kaspersky Labs on 2019-10-29
These two vulnerabilities allow an attacker to execute arbitrary code in the browser, obtain sensitive information, bypass security restrictions and perform unauthorized operations or cause a denial of service. Google acknowledges that hackers have exploited the CVE-2019-13720 vulnerability to launch attacks on Chrome users. Detailed information about security vulnerabilities is not yet available.
Chrome users, please upgrade your browser as soon as possible!
The post Alert: Please update Google Chrome to the latest version now appeared first on InfoTech News.
Source : Haxf4rall