Google patches first Chrome zero-day of the year


Google has patched a high-severity vulnerability in the Chrome browser which was apparently being used as a zero-day in the wild. In a security advisory, Google said it addressed CVE-2026-2441, a “use after free in CSS in Google Chrome prior to 145.0.7632.75”.

This bug, given a severity score of 8.3/10 (high), allows threat actors to execute arbitrary code inside a sandbox via a crafted HTML page. Usually, Google would push all Chrome updates automatically, so if you haven’t disabled automatic updates, just restart the browser and make sure it’s running 145.0.7632.75/76 for Windows and MacOS, or 144.0.7559.75 for Linux.

Read more…
Source: TechRadar News


Sign up for the Cyber Security Review Newsletter
The latest cyber security news and insights delivered right to your inbox


Related:

  • Cisco Warns of Critical Vulnerability Revealed in ‘Vault 7’ Data Dump

    March 20, 2017

    Cisco Systems warned customers on Friday of a critical vulnerability that could allow an attacker to execute arbitrary code and obtain full control on more than 300 different models of its switches and routers. Cisco said it became aware of the vulnerability after WikiLeaks released its Vault 7 cache of documents that revealed the existence ...