Chrome update 89.0.4389.128 addresses a 0-day vulnerability. Chrome 90 is delayed.

Google has released an update for Chrome 89.0.4389.128, which addresses two vulnerabilities (CVE-2021-21206, CVE-2021-21220) that have available working exploits (0-day). The CVE-2021-21220 vulnerability was exploited to hack Chrome during the Pwn2Own 2021 competition.

Exploitation of the mentioned vulnerability occurs through the execution of specially crafted WebAssembly code (the vulnerability is caused by an error in the WebAssembly virtual machine, allowing data to be written or read from arbitrary memory addresses). It’s noted that the shown exploit does not allow bypassing sandbox isolation, and a full attack requires discovering another vulnerability to escape the sandbox (such a vulnerability was demonstrated for Windows during the Pwn2Own 2021 competition).

An example of the exploit for this issue was published on GitHub after a fix was made to the V8 engine, but before a browser update was established based on it (even if the exploit had not been published, attackers could recreate it based on change analysis in the V8 repository, which has happened before due to the situation where a fix in V8 was published, but products based on it were not yet updated).

Additionally, it can be noted that the release schedule for Chrome 90 for Linux, Windows, and macOS has shifted. This release was initially scheduled for April 13 but was not published yesterday; only the Android version was released. Today, an additional beta release for Chrome 90 was created. No new release date has been announced.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster