Google Chrome Hit With Zero Day Bug, Again. Here's Why You Should Update Your App

2022-08-20 22:46:24
关注

Google Chrome is asking users to update their browsers after the Internet giant revealed hackers are privy to a "zero-day" bug that could give attackers access to your private information.

A zero-day bug is a security vulnerability known to hackers before the vendor is aware, and it's already being used by hackers.

While Google says it has resolved 11 security vulnerabilities ranging from medium to critical impact in its latest update, one may still be known to hackers.

"Google is aware that an exploit for CVE-2022-2856 exists in the wild," according to an August 16 press release.

CVE-2022-2856 marks the fifth zero-day that Google has experienced in 2022, per Forbes.

Since zero-day hacks may be unbeknownst to the vendor, there is no patch for the vulnerability.

Google has yet to share specific details about the zero-day bug but said in their press release that "access to bug details and links may be kept restricted until a majority of users are updated with a fix."

However, they do reveal that it was reported by hackers from the Google Threat Analysis Group on July 9, and described the issue as "Insufficient validation of untrusted input in Intents." Here, "intents" is how Chrome processes user input, meaning a possible input could be interfering with Google's code.

The day before reporting the vulnerability, Google Chrome shared two tweets about zero-day bugs.

What are zero-day exploits — and how does #Chrome protect you from them?

ICYMI: Watch as Security Sheriff Adrian Taylor explains why these bugs are the highest priority for Chrome's security team → https://t.co/p3QNGQQ7Cz pic.twitter.com/JjUbdW3Pa4

— Chrome (@googlechrome) August 15, 2022

In the video, "Security Sheriff" Adrian Taylor says "all software can have bugs, even that built to the highest engineering standards like Chrome." Explaining that "malicious websites" may use bugs to steal your information, he said, "We address any security bug with great urgency, but with even more urgency for zero-day bugs."

As Chrome gains more visibility into how attackers use zero-day bugs, we're becoming more sophisticated in how we discover and fix vulnerabilities. Learn how we're adding even more layers of defense that make it difficult for attackers to bypass: https://t.co/s61p1Sa1kS

— Chrome (@googlechrome) August 15, 2022

To best protect yourself, it's advised to update your Google Chrome browser and app. While it should automatically update, users can check by going to About Google Chrome in your browser menu, which will force check for any possible updates.

参考译文
谷歌Chrome与零日Bug,再次击中。以下是你应该更新应用程序的原因
谷歌Chrome要求用户更新浏览器,因为这家互联网巨头透露黑客已经掌握了影响用户隐私信息的“零日漏洞”。所谓零日漏洞,是指黑客在供应商尚未察觉之前就知道的安全漏洞,并且已经被黑客加以利用。虽然谷歌表示,它在其最新更新中修复了11个从中等到关键级别的安全漏洞,但其中可能仍有一个是黑客所知的。谷歌在8月16日的一份声明中表示:“我们知道CVE-2022-2856的漏洞利用目前已经在野使用。”根据福布斯的报道,CVE-2022-2856是谷歌在2022年经历的第五个零日漏洞。由于零日攻击是供应商尚未察觉的漏洞,因此没有现成的补丁可用。谷歌尚未透露该零日漏洞的具体细节,但他们在声明中指出,“在绝大多数用户都接收到修复补丁前,我们可能会限制对漏洞细节和链接的访问。”然而,他们透露,该漏洞是由谷歌威胁分析小组的黑客于7月9日报告的,并将该问题描述为“对不可信输入在Intents中的验证不充分。”这里的“Intents”是Chrome处理用户输入的方式,意味着某种可能的输入正在干扰谷歌的代码。在报告该漏洞的前一天,谷歌Chrome发布了两条关于零日漏洞的推文。什么是零日漏洞——Chrome又是如何保护你免受其影响的?如果你错过了之前的推文,点击观看安全专家Adrian Taylor讲解为何这些漏洞对Chrome的安全团队来说是最高优先级的——https://t.co/p3QNGQQ7Cz pic.twitter.com/JjUbdW3Pa4— Chrome (@googlechrome) 2022年8月15日在视频中,被称作“安全警长”的Adrian Taylor表示:“即使是像Chrome这样按照最高工程标准构建的软件,也可能会存在漏洞。”他解释说,“恶意网站”可能会利用这些漏洞窃取你的信息,并表示,“我们会以极大的紧迫性解决任何安全漏洞,但对零日漏洞的处理更为紧迫。”随着Chrome对攻击者如何利用零日漏洞有了更深入的了解,我们在发现和修复漏洞方面也变得更为复杂和高效。了解我们是如何增加更多防御层,以使攻击者难以绕过:https://t.co/s61p1Sa1kS— Chrome (@googlechrome) 2022年8月15日为了更好地保护自己,建议你更新你的谷歌Chrome浏览器和应用程序。虽然Chrome应该会自动更新,但用户可以通过在浏览器菜单中选择“关于Google Chrome”来手动检查是否还有其他更新。
您觉得本篇内容如何
评分

评论

您需要登录才可以回复|注册

提交评论

广告
提取码
复制提取码
点击跳转至百度网盘