Description

Google has issued an urgent update for its Chrome browser to fix two significant security vulnerabilities that could enable attackers to take control of users’ systems. These vulnerabilities, identified as CVE-2024-10487 and CVE-2024-10488, impact Chrome on Windows, Mac, and Linux platforms, making it crucial for users to update their browsers promptly. CVE-2024-10487, categorized as Critical, involves an "out of bounds write" vulnerability within the Dawn graphics library. This flaw may allow attackers to corrupt memory and execute malicious code on affected devices. Reported by Apple Security Engineering and Architecture on October 23rd, this incident underscores the importance of collaboration in cybersecurity among major technology firms. The second vulnerability, CVE-2024-10488, is classified as High and relates to a "use after free" issue in WebRTC, which supports real-time communication in Chrome. This vulnerability could enable attackers to exploit freed memory, resulting in crashes or, in more serious scenarios, arbitrary code execution. Security researcher Cassidy Kim identified and reported the issue on October 18th. The new updates, available as versions 130.0.6723.91/.92 for Windows and Mac, and 130.0.6723.91 for Linux, will be rolled out to users in the coming days. Google encourages all users to update their Chrome browsers immediately by going to “Help” -> “About Google Chrome,” where the browser will automatically check for and install the latest updates.