Chrome update 100.0.4896.127 addresses a 0-day vulnerability

Google has released Chrome version 100.0.4896.127 for Windows, Mac, and Linux, which fixes a critical vulnerability (CVE-2022-1364) that is already being exploited by attackers (0-day). Details are not disclosed yet; it is known that the 0-day vulnerability is caused by improper type handling (Type Confusion) in the JavaScript engine Blink, allowing an object with an incorrect type to be processed. This can enable, for example, the construction of a 64-bit pointer based on a combination of two different 32-bit values to gain access to the entire address space of the process. Users are advised not to wait for the automatic update delivery but to check for its availability and initiate installation through the menu 'Chrome > Help > About Google Chrome'.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster