Google has updated Chrome to version 116.0.5845.140/.141 through its stable and extended stable channels for Mac, Linux, and Windows. The main goal of this update is to solve a security issue in Chrome. Notably, this upgrade includes a "high severity" security patch, and its rollout will take place gradually over the next few days and weeks. This update has successfully fixed a significant vulnerability identified as CVE-2023-4572 and rated as "high severity. The specific flaw, referred to as "Use after free in MediaStream," has been fixed, and credit for finding this problem goes to fwnfwn (@_fwnfwn). When dynamic memory is managed incorrectly while a program is running, there is a flaw known as "Use After Free" (UAF) that can be exploited by adversaries. Basically, attackers may be able to influence the program using this mistake if the program doesn't remove the pointer to a memory address after freeing it. Google has announced a change in strategy regarding security updates for the stable channel. The business will now start sending out weekly security updates, and the modification intends to close the gap in the Chrome release cycle and speed up the quick fix of vulnerabilities and significant issues. Updates addressing security-related and other high-impact vulnerabilities will now be scheduled weekly instead of every four weeks, which will speed up the execution of security patches. Following the patching of a security flaw in Chrome, the procedure involves making the corrected source code for Chrome available to everyone. The patch gets put out on the stable channel after being carefully tested and assessed.
A critical security vulnerability has been found in Advanced Custom Fields Extended, a popular WordPress utility plugin used on more than 100000 websites. The issue is tracked as C...
A newly advertised malware toolkit known as K.G.B RAT has surfaced across underground forums, drawing attention for its promise of being a “fully undetectable” remote-access pa...
A malicious Rust package named evm-units was recently discovered masquerading as a legitimate utility crate for Ethereum Virtual Machine (EVM) unit handling. Instead of providing f...