N3philimUtu Posted March 22, 2024 Report Share Posted March 22, 2024 (edited) El 15 de mayo, Google publicó nueve parches para Chrome, uno de ellos de día cero, el tercero esta semana reportado por el gigante tecnológico. Los parches coinciden con el anuncio del equipo de Chrome de Google del lanzamiento de Chrome 125 en el canal estable para Windows, Mac y Linux. Estas actualizaciones se implementarán en los próximos días/semanas. Haga clic para obtener más cobertura especial Los profesionales de seguridad dijeron que el error más importante fue el día cero de alta gravedad (CVE-2024-4947), descrito por NIST como una confusión de tipos en V8 en Google Chrome anterior a 125.0.6422.60 que permitía a un atacante remoto ejecutar código arbitrario dentro de un sandbox a través de una página HTML diseñada. Google dijo que Vasily Berdnikov y Boris Larin de Kaspersky informaron sobre CVE-2024-4947 el 13 de mayo. La compañía también señaló que es consciente de que existe un exploit para CVE-2024-4947 en la naturaleza. "Más que cualquier cambio en el propio Chrome, [estos días cero] son un reflejo de que los atacantes continúan centrándose en los navegadores en general y en Chrome en particular como su objetivo más preciado", dijo Lionel Litty, arquitecto jefe de seguridad de Menlo Security. "Un error explotable en Chrome a menudo significa la capacidad de apuntar no solo a una gran cantidad de usuarios de Chrome en computadoras de escritorio y Android, sino también a los usuarios de Edge y otros navegadores más especializados que también se basan en Chromium". Patrick Tiquet, vicepresidente de seguridad y arquitectura de Keeper Security, dijo que estas fallas de alta seguridad son graves y los equipos deberían corregirlas de inmediato. “Con CVE-2024-4947 siendo explotado activamente en la naturaleza, los atacantes remotos pueden ejecutar código arbitrario en los sistemas afectados, comprometiéndolos potencialmente por completo y permitiendo el robo de datos, la manipulación del sistema o una mayor explotación, lo que hace que sea fundamental para los usuarios de Chrome actualizar sus navegadores. lo antes posible”, afirmó Tiquet. Silent installation Silent installation Cita https://www.mediafire.com/file/psnc7bgucy0kece/Google+Chrome+125.0.6422.113+AIO+Silent+Install.7z/file https://mir.cr/VKT1IY3U Windows 7/8 Silent installation Google Chrome 109.0.5414.120 AIO windows 7 last version Install Silent Cita https://www.mediafire.com/file/g170...ome+109.0.5414.120+AIO+Install+Silent.7z/file Edited May 26, 2024 by N3philimUtu Link to comment Share on other sites More sharing options...
N3philimUtu Posted March 29, 2024 Author Report Share Posted March 29, 2024 update Link to comment Share on other sites More sharing options...
N3philimUtu Posted April 12, 2024 Author Report Share Posted April 12, 2024 https://chromium.googlesource.com/chromium/src/+log/123.0.6312.99..123.0.6312.118?pretty=fuller&n=10000 Link to comment Share on other sites More sharing options...
N3philimUtu Posted April 18, 2024 Author Report Share Posted April 18, 2024 Chrome 124 works on a bottom bar for the Google app Chrome experimented with a bottom bar interface a long time ago on Android, and its iOS version recently received an optional fully bottom-based interface. While there isn’t any evidence that Google is working on something like that for Chrome for Android, the company might do the second best thing and add a bottom bar to Chrome custom tabsopened via the Google app. That’s basically all we know about it at this point, with Chrome 124 only showing early evidence that this is coming. The bottom bar might house Google-specific options or ways to dive deeper into search, but that’s just speculation. Chrome 124 preps a Circle-to-Search-style feature for desktops Google is working on a serious Lens upgrade for Chrome on desktop, and we might just see a new Android feature make its way to the browser. It basically works by turning your current tab into a screenshot that you can use Lens on. Right now, that’s about everything we can glean so far, but given that Google recently introduced Circle to Search on select Samsung and Google phones, we can imagine that you’ll be able to select different portions of the visible website and use it to dive into a search session. Chrome 124 lays groundwork for a new keyboard shortcut Chrome 124 is adding preliminary work for a new keyboard shortcut. Rather than remembering your operating system’s sometimes convoluted way to exit a fullscreen window, you’ll simply be able to pr Link to comment Share on other sites More sharing options...
N3philimUtu Posted April 25, 2024 Author Report Share Posted April 25, 2024 The version of Google Chrome installed on the remote Windows host is prior to 124.0.6367.78. It is, therefore, affected by multiple vulnerabilities as referenced in the 2024_04_stable-channel-update-for-desktop_24 advisory. - Type Confusion in ANGLE. (CVE-2024-4058) - Out of bounds read in V8 API. (CVE-2024-4059) - Use after free in Dawn. (CVE-2024-4060) Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number. Solution Upgrade to Google Chrome version 124.0.6367.78 or later. Link to comment Share on other sites More sharing options...
N3philimUtu Posted May 10, 2024 Author Report Share Posted May 10, 2024 The Stable channel has been updated to 124.0.6367.201/.202 for Mac and Windows and 124.0.6367.201 for Linux which will roll out over the coming days/weeks. A full list of changes in this build is available in the Log. The Extended Stable channel has been updated to 124.0.6367.201 for Mac and Windows which will roll out over the coming days/weeks. Security Fixes and Rewards Note: Access to bug details and links may be kept restricted until a majority of users are updated with a fix. We will also retain restrictions if the bug exists in a third party library that other projects similarly depend on, but haven’t yet fixed. This update includes 1 security fix. Below, we highlight fixes that were contributed by external researchers. Please see the Chrome Security Page for more information. [N/A][339266700] High CVE-2024-4671: Use after free in Visuals. Reported by Anonymous on 2024-05-07 Google is aware that an exploit for CVE-2024-4671 exists in the wild. We would also like to thank all security researchers that worked with us during the development cycle to prevent security bugs from ever reaching the stable channel. Interested in switching release channels? Find out how here. If you find a new issue, please let us know by filing a bug. The community help forum is also a great place to reach out for help or learn about common issues. Daniel Yip Link to comment Share on other sites More sharing options...
N3philimUtu Posted May 14, 2024 Author Report Share Posted May 14, 2024 update Link to comment Share on other sites More sharing options...
N3philimUtu Posted May 17, 2024 Author Report Share Posted May 17, 2024 Chrome Stable for iOS Update Thursday, May 16, 2024 Hi everyone! We've just released Chrome Stable 125 (125.0.6422.51) for iOS; it'll become available on App Store in the next few hours. This release includes stability and performance improvements. You can see a full list of the changes in the Git log. If you find a new issue, please let us know by filing a bug. Krishna Govind Google Chrome Link to comment Share on other sites More sharing options...
N3philimUtu Posted May 26, 2024 Author Report Share Posted May 26, 2024 Chrome for Android Update Thursday, May 23, 2024 Hello, Everyone! We've just released Chrome 125 (125.0.6422.112/.113) for Android: it'll become available on Google Play over the next few days. This release includes stability and performance improvements. You can see a full list of the changes in the Git log. If you find a new issue, please let us know by filing a bug. Android releases contain the same security fixes as their corresponding Desktop (Windows & Mac: 125.0.6422.112/.113 and Linux:125.0.6422.112 ) unless otherwise noted. Krishna Govind Link to comment Share on other sites More sharing options...
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now