Free Republic
Browse · Search
General/Chat
Topics · Post Article

Skip to comments.

Google wants you to update Chrome right now (ZERO-DAY Exploit in Chrome Browser)
TechSpot ^ | Mar 7, 2019 | Dean Pennington

Posted on 03/08/2019 7:49:10 AM PST by dayglored

Bottom line: Google is urging Chrome users to update their browsers immediately after a zero-day exploit that could give hackers direct access to a user's OS has been found. The most recent version is 72.0.3626.121, and it's the version you want to be running to make sure you're safe from this exploit.

Google is urging users to update Chrome across all platforms after a critical vulnerability was discovered and patched.

The vulnerability exploits a security flaw known as CVE-2019-5786. The security flaw is a memory management issue in Chrome's FileReader which gives hackers the opportunity to inject and execute malicious code.

FileReader is a embedded program in most browsers that allows web apps to read the contents of a user's local file system. The vulnerability identified by Google allows malicious code to leave Chrome's security environment and run commands on the underlying OS.

Well-known Chrome security researcher Justin Schuh concisely addressed the urgency of this update on Twitter:

Also, seriously, update your Chrome installs... like right this minute. #PSA

— Justin Schuh (@justinschuh) March 6, 2019

Google is calling this a "zero-day" vulnerability, meaning that the bad guys figured out how to exploit it before the good guys were able to find and patch it.

The version of Chrome you should be running is 72.0.3626.121, released at the beginning of March 2019. To check your version number, type chrome://settings/help into the address bar. From there, you will be able to see your version number. Just going to that page will trigger an update check, and Chrome will prompt you to relaunch it when finished. You can also manually download the latest version of Chrome here.

Stay safe out there.


TOPICS: Business/Economy; Computers/Internet; Hobbies
KEYWORDS: chrome; google; windowspinglist; zeroday
Navigation: use the links below to view more comments.
first 1-2021-4041-47 next last
Most Chrome installs will update themselves automatically when restarted, so the easiest way to update is just restart the browser.
1 posted on 03/08/2019 7:49:10 AM PST by dayglored
[ Post Reply | Private Reply | View Replies]

To: Abby4116; afraidfortherepublic; aft_lizard; AF_Blue; AppyPappy; arnoldc1; ATOMIC_PUNK; bajabaja; ...
Google Chrome Browser ZERO-DAY Exploit ... PING!

You can find all the Windows Ping list threads with FR search: just search on keyword "windowspinglist".

2 posted on 03/08/2019 7:49:55 AM PST by dayglored ("Listen. Strange women lying in ponds distributing swords is no basis for a system of government."`)
[ Post Reply | Private Reply | To 1 | View Replies]

To: dayglored

Don’t have it, even though every ‘free’ app tries to install it.......................


3 posted on 03/08/2019 7:51:07 AM PST by Red Badger (We are headed for a Civil War. It won't be nice like the last one....................)
[ Post Reply | Private Reply | To 1 | View Replies]

To: dayglored

I am sure I am like most and have Chrome set to automatically update. Got current version: Version 72.0.3626.121 (Official Build) (64-bit)


4 posted on 03/08/2019 7:51:13 AM PST by Reno89519 (No Amnesty! No Catch-and-Release! Just Say No to All Illegal Aliens! Arrest & Deport!)
[ Post Reply | Private Reply | To 1 | View Replies]

To: dayglored
Another good article on this from The Register:
Put down the cat, coffee, beer pint, martini, whatever you're holding, and make sure you've updated Chrome (unless you enjoy being hacked)

5 posted on 03/08/2019 7:51:24 AM PST by dayglored ("Listen. Strange women lying in ponds distributing swords is no basis for a system of government."`)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Swordmaker; ShadowAce; ThunderSleeps

*PING* for your lists...


6 posted on 03/08/2019 7:52:19 AM PST by dayglored ("Listen. Strange women lying in ponds distributing swords is no basis for a system of government."`)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Red Badger

Yeah I’m going to lt Google, totally government-connected and selling its users info to anyone anywhere, supply me with my internet browser. Right.


7 posted on 03/08/2019 7:53:38 AM PST by Steely Tom ([Seth Rich] == [the Democrat's John Dean])
[ Post Reply | Private Reply | To 3 | View Replies]

To: dayglored

I just checked, the version of Chrome I am running now is the right (latest) one. Must have updated automatically.


8 posted on 03/08/2019 7:54:39 AM PST by G. W. McLintock
[ Post Reply | Private Reply | To 1 | View Replies]

To: dayglored

I checked and am up to date.

Thank you for the heads up!


9 posted on 03/08/2019 7:56:38 AM PST by chris37 (No wall? No vote.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: dayglored

Done automatically.


10 posted on 03/08/2019 7:57:30 AM PST by Carriage Hill (A society grows great when old men plant trees, in whose shade they know they will never sit.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: dayglored

Who here’s stupid enough to still be using ANY google-linked program?

I mean, if I want my personal data, web-browsing history, passwords, credit card data and all that to go directly to the NSA/DOJ/INTERPOL I’d just send it to them, why use an intermediary?


11 posted on 03/08/2019 8:00:20 AM PST by normbal (normbal. somewhere in socialist occupied America)
[ Post Reply | Private Reply | To 1 | View Replies]

To: dayglored; bitt

:: FileReader is a embedded program in most browsers that allows web apps to read the contents of a user’s local file system ::

Yet, everyone will pass this by and dutifully update their Chrome. Then, they will get the security agreement, never read it and click “I Agree”.


12 posted on 03/08/2019 8:00:22 AM PST by Cletus.D.Yokel (Catastrophic, Anthropogenic Climate Alterations: The acronym explains the science.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: dayglored

Thanks for posting this. I’m running Chrome. And since yesterday why I try to go to the Verizon website, I get redirected to some fake site. Now maybe I know why.


13 posted on 03/08/2019 8:00:46 AM PST by Leaning Right (I have already previewed or do not wish to preview this composition.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: dayglored

Thank you.


14 posted on 03/08/2019 8:02:25 AM PST by MarMema (don't forget to stock up on dogfood)
[ Post Reply | Private Reply | To 1 | View Replies]

To: normbal

They already have that stuff.

Hopefully they are reading FR—they might learn something!


15 posted on 03/08/2019 8:03:18 AM PST by cgbg (Hidden behind the social justice warrior mask is corruption and sexual deviance.)
[ Post Reply | Private Reply | To 11 | View Replies]

To: Reno89519; dayglored
I am sure I am like most and have Chrome set to automatically update. Got current version: Version 72.0.3626.121 (Official Build) (64-bit)

Interesting! I am using the Brave browser. Just checked my version and this is what I got. Looks like Brave has "blended" with Google Chrome a little too closely for my personal comfort level.

Version 0.60.48 Chromium: 72.0.3626.121 (Official Build) (64-bit)

Dayglored, what is your professional opinion?

16 posted on 03/08/2019 8:04:00 AM PST by Perseverando (For Progressives, Islamonazis, Statists, Commies & other DemoKKKrats: It's all about PEOPLE CONTROL!)
[ Post Reply | Private Reply | To 4 | View Replies]

To: dayglored; Whenifhow; null and void; aragorn; EnigmaticAnomaly; kalee; Kale; 2ndDivisionVet; ...

p


17 posted on 03/08/2019 8:09:52 AM PST by bitt (Is the PAIN coming???)
[ Post Reply | Private Reply | To 1 | View Replies]

To: dayglored

Gargoyle products are not welcome on my machines so no problems here!


18 posted on 03/08/2019 8:13:10 AM PST by rockrr ( Everything is different now...)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Perseverando

Never heard of it. I am stuck using the most popular browsers, so that I can frequently check our company websites to ensure they are working correctly. So I use chrome, which is over 75% of the browser market, Safari, and Microsoft Edge.


19 posted on 03/08/2019 8:14:24 AM PST by Reno89519 (No Amnesty! No Catch-and-Release! Just Say No to All Illegal Aliens! Arrest & Deport!)
[ Post Reply | Private Reply | To 16 | View Replies]

To: dayglored

Google...shove it.


20 posted on 03/08/2019 8:16:17 AM PST by WKUHilltopper
[ Post Reply | Private Reply | To 1 | View Replies]


Navigation: use the links below to view more comments.
first 1-2021-4041-47 next last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
General/Chat
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson