Update Chrome and ChromeOS to fix critical security issues


Google has released updates for the Chrome browser and the ChromeOS operating system.

On October 6, Google released a Stable Channel Update for Desktop. This is the most important one for desktop users. It brings Chrome to version 155.0.8059.39 for Linux and versions 154.0.8037.39/.40 for Windows and Mac. The update includes 247 security fixes including four rated Critical.

On the same day, Google released version 155.0.8059.39 for Android, to a small percentage of users. It may not be available on Google Play for everyone yet but keep an eye out for it. Google says it includes stability and performance improvements.

Read more…
Source:  MalwareBytes Labs


Sign up for the Cyber Security Review Newsletter
The latest cyber security news and insights delivered right to your inbox


Related:

  • How Unsecure gRPC Implementations Can Compromise APIs, Applications

    August 17, 2020

    Enterprises are turning to microservice architecture to build future-facing applications. Microservices allow enterprises to efficiently manage infrastructure, easily deploy updates or improvements, and help IT teams innovate, fail, and learn faster. It also allows enterprises to craft applications that can easily scale with demand. Additionally, as enterprises switch architectures — jumping from the traditional monolithic to ...

  • Patch List: Adobe, Citrix, Intel, and vBulletin Vulns

    August 14, 2020

    Vulnerabilities expose enterprises’ systems to compromise. Now that many employees are working from home and operating devices outside the more secure office environments, the need to patch vulnerabilities as soon as they are discovered has become even more pressing. Aside from Microsoft, the following vendors also released patches recently: Adobe, Citrix, Intel, and vBulletin. We rounded ...

  • XCSSET Mac Malware: Infects Xcode Projects, Performs UXSS Attack on Safari, Other Browsers, Leverages Zero-day Exploits

    August 13, 2020

    Trend Micro has discovered an unusual infection related to Xcode developer projects. Upon further investigation, we discovered that a developer’s Xcode project at large contained the source malware, which leads to a rabbit hole of malicious payloads. Most notable in our investigation is the discovery of two zero-day exploits: one is used to steal cookies ...

  • Internet Explorer and Windows zero-day exploits used in Operation PowerFall

    August 12, 2020

    In May 2020, Kaspersky technologies prevented an attack on a South Korean company by a malicious script for Internet Explorer. Closer analysis revealed that the attack used a previously unknown full chain that consisted of two zero-day exploits: a remote code execution exploit for Internet Explorer and an elevation of privilege exploit for Windows. Unlike ...

  • Re­VoL­TE attack can decrypt 4G (LTE) calls to eavesdrop on conversations

    August 12, 2020

    A team of academics has detailed this week a vulnerability in the Voice over LTE (VoLTE) protocol that can be used to break the encryption on 4G voice calls. Named ReVoLTE, researchers say this attack is possible because mobile operators often use the same encryption key to secure multiple 4G voice calls that take place via ...

  • August Patch Tuesday Fixes Critical IE, Important Windows Vulnerabilities Exploited in the Wild

    August 11, 2020

    The August batch of Patch Tuesday updates includes 120 updates for the Microsoft suite, with 17 fixes rated as Critical, and the remaining 103 ranked as Important. CVE-2020-1380 is a critical Internet Explorer (IE) vulnerability that can be abused for remote code execution (RCE), while CVE-2020-1464 is a Windows 10 security gap that can be ...