GitKraken Vulnerability Prompts Action From GitHub, GitLab, Bitbucket

Developers of Git GUI client GitKraken have addressed a vulnerability resulting in the generation of weak SSH keys, and they are prompting users to revoke and renew their keys.

Discovered in the open source library that the Git GUI client uses for SSH key generation, the issue affects all keys issued using versions 7.6.x, 7.7.x, and 8.0.0 of GitKraken.

The security hole was identified in late September and was addressed with the release of GitKraken version 8.0.1. The SSH key generation library was replaced with a new one.

Due to the presence of the vulnerability in multiple versions of GitKraken, users are advised to regenerate their SSH keys even if they have already updated to the patched version.

“We are not aware of any accounts being compromised due to this flaw. We will continue to work toward the highest security standards possible for all of our users,” the GitKraken team said.

Git hosting service providers Azure DevOps, Bitbucket, GitHub, and GitLab have been alerted of the issue, so that the weak public keys in use could be revoked. The platforms have already taken the necessary steps to address the issue.

GitHub on Monday announced that it has revoked the weak SSH keys generated using the GitKraken client, as well as “other potentially weak keys created by other clients that may have used the same vulnerable dependency.”

The code hosting service also added new protections to ensure that vulnerable versions of GitKraken can’t add new weak keys. However, other weakly-generated keys that are in use on GitHub.com might come from additional third-party clients that use the vulnerable library.

“The nature of this vulnerability prevents us from identifying all possible weak SSH keys produced by this library and vulnerable clients that used it. Out of an abundance of caution, we’ve also revoked other potentially weak keys associated with these scenarios and blocked their use,” GitHub says.

The platform has already notified affected users, prompting them to regenerate their keys. The same did GitLab, which also announced that it blocked known weak keys.

“[The weak keys] could enable an attacker to gain unauthorized access to an account or repositories on GitLab.com or a self-managed instance,” GitLab said, adding that it has no evidence that GitLab.com or projects that use GitKraken might have been compromised.

Bitbucket Cloud too revoked identified weak keys and prompted users to generate new keys, adding that no evidence of compromise was found.

Related: Google Pledges $1 Million to Secure Open Source Program

Related: Vulnerability in Lasso Library Impacts Products From Cisco, Akamai

Related: Library Dependencies and the Open Source Supply Chain Nightmare

view counter

Ionut Arghire is an international correspondent for SecurityWeek.

Previous Columns by Ionut Arghire:
Tags:

http://feedproxy.google.com/~r/securityweek/~3/4f7ORceX_20/gitkraken-vulnerability-prompts-action-github-gitlab-bitbucket




Google Patches Four Severe Vulnerabilities in Chrome

Google this week announced the release of an updated Chrome version for Windows, Mac and Linux, to address a total of four high-severity vulnerabilities in the browser.

Tracked as CVE-2021-37977, the most severe of these security holes could be exploited to achieve arbitrary code execution on a target system.

The flaw, described as a use-after-free bug in Garbage Collection, was reported last month by an anonymous researcher. Google says it paid a $10,000 bounty reward for the finding.

Now rolling out to desktop users as Chrome version 94.0.4606.81, the new browser iteration also addresses two heap buffer overflow vulnerabilities in Blink (CVE-2021-37978) and WebRTC (CVE-2021-37979).

The issues were reported by Yangkang (@dnpushme) of 360 ATA and Marcin Towalski of Cisco Talos, respectively. Google says it handed out $7,500 to each of the reporting researchers.

A fourth high-severity bug addressed with the new Chrome release is CVE-2021-37980, an inappropriate implementation in Sandbox. Yonghwi Jin (@jinmo123), the reporting researcher, received a $3,000 bounty reward for the finding.

Attackers could exploit these vulnerabilities through specially crafted webpages to compromise a visitor’s system and potentially execute code in the context of the browser.

Google says the Chrome extended stable channel too was updated to version 94.0.4606.81 for Windows and Mac.

The search giant made no mention of any of these vulnerabilities being exploited in targeted attacks. So far this year, however, there have been more than a dozen documented zero-day exploits targeting the Chrome and Android platforms.

Related: Google Patches Two More Exploited Zero-Day Vulnerabilities in Chrome

Related: Google Warns of Exploited Zero-Days in Chrome Browser

Related: Google Working on Improving Memory Safety in Chrome

view counter

Ionut Arghire is an international correspondent for SecurityWeek.

Previous Columns by Ionut Arghire:
Tags:

http://feedproxy.google.com/~r/securityweek/~3/rgNGjlx-ARA/google-patches-four-severe-vulnerabilities-chrome




Apache Releases Another Patch for Actively Exploited HTTP Server Zero-Day

The Apache HTTP Server Project on Thursday announced the release of another update in response to a recently discovered zero-day vulnerability after determining that the initial fix was incomplete.

The vulnerability, tracked as CVE-2021-41773, can be exploited for path traversal and remote code execution. The flaw impacts Apache HTTP Server 2.4.49 and it has been exploited in attacks, so it’s important that organizations install the patches as soon as possible.

Apache HTTP Server 2.4.50 was initially released to patch CVE-2021-41773, but the fix was not sufficient. Another CVE identifier, CVE-2021-42013, has been assigned, and HTTP Server 2.4.51 was released on Thursday in an attempt to deliver a more complete patch.

“An attacker could use a path traversal attack to map URLs to files outside the directories configured by Alias-like directives,” the developers explained in a new advisory. “If files outside of these directories are not protected by the usual default configuration ‘require all denied’, these requests can succeed. If CGI scripts are also enabled for these aliased paths, this could allow for remote code execution.”

When the security hole came to light, there were roughly 112,000 potentially vulnerable internet-exposed servers running the affected HTTP Server 2.4.49 version. At the time of writing, that number has dropped to roughly 98,000, with a majority of servers located in North America and Western Europe. The number of servers running version 2.4.50 is currently at 12,000, and only roughly 1,600 have been updated to version 2.4.51, according to data from Shodan.

Proof-of-concept (PoC) exploit code was made public shortly after disclosure, and threat intelligence companies have been seeing attempts to exploit the flaw, as well as internet scans looking for vulnerable systems.

“Since this is primarily a path traversal bug, the majority of the exploitation we see is focused on two specific paths: /etc/ passwd and /bin/ sh. These would make sense, as attackers are going to try and leverage this for access by accessing credentials or obtaining direct access to a shell,” Cisco’s Talos unit explained.

“There appear to be several different groups of actors exploiting this vulnerability,” Talos added. “Some are just scanners that appear to be scanning for potentially vulnerable hosts. Others appear to be iterating through a large list of domains with varying generic HTTP scanning leveraging this vulnerability. And there’s another group operating at a much lower volume that are keenly interested in this specific vulnerability.”

It’s unclear exactly when the attacks started. The vulnerability had already been targeted in the wild when version 2.4.50 was released on October 4. Threat intelligence company GreyNoise reported seeing the first scans for CVE-2021-41773 on October 3, at which point a patch had already been committed to the HTTP Server source code — the patch was committed on September 29.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday urged organizations to immediately patch their installations, warning them not to wait until after the holiday weekend.

“CISA is also seeing ongoing scanning of vulnerable systems, which is expected to accelerate, likely leading to exploitation,” the agency said. 

Related: Hackers Scanning for Apache Tomcat Servers Vulnerable to Ghostcat Attacks

Related: Critical Apache Struts Vulnerability Exploited in Live Attacks

view counter

Eduard Kovacs (@EduardKovacs) is a contributing editor at SecurityWeek. He worked as a high school IT teacher for two years before starting a career in journalism as Softpedia’s security news reporter. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Previous Columns by Eduard Kovacs:
Tags:

http://feedproxy.google.com/~r/securityweek/~3/tZjrfk8X4W8/apache-releases-another-patch-actively-exploited-http-server-zero-day




Cisco Patches High-Severity Vulnerabilities in Security Appliances, Business Switches

Cisco this week released patches for multiple high-severity vulnerabilities affecting its Web Security Appliance (WSA), Intersight Virtual Appliance, Small Business 220 switches, and other products.

Successful exploitation of these vulnerabilities could allow attackers to cause a denial of service (DoS) condition, execute arbitrary commands as root, or elevate privileges.

Two high-severity issues (CVE-2021-34779, CVE-2021-34780) were found in the Link Layer Discovery Protocol (LLDP) implementation for Small Business 220 series smart switches, leading to the execution of arbitrary code and a denial of service condition.

The software update released for the enterprise switch series also resolves four medium-severity security flaws that could result in LLDP memory corruption on an affected device.

Another severe vulnerability is an insufficient input validation in the Intersight Virtual Appliance. Tracked as CVE-2021-34748, the security hole could lead to the execution of arbitrary commands with root privileges.

This week Cisco also resolved two high-severity vulnerabilities in the ATA 190 series and ATA 190 series multiplatform (MPP) software. Tracked as CVE-2021-34710 and CVE-2021-34735, the flaws could be exploited for remote code execution and to cause a denial of service (DoS) condition, respectively.

One of these vulnerabilities was reported to Cisco by firmware security company IoT Inspector, which described its findings in an advisory published on Thursday.

Cisco also addressed an improper memory management flaw in AsyncOS for Web Security Appliance (WSA) that could lead to DoS, as well as a race condition in the AnyConnect Secure Mobility Client for Linux and macOS that could be abused to execute arbitrary code with root privileges.

Another high-severity flaw addressed this week is CVE-2021-1594, an insufficient input validation in the REST API of Cisco Identity Services Engine (ISE). An attacker in a man-in-the-middle position able to decrypt HTTPS traffic between two ISE personas on separate nodes could exploit the flaw to execute arbitrary commands with root privileges.

Cisco also released patches for multiple medium-severity flaws affecting TelePresence CE and RoomOS, Smart Software Manager On-Prem, 220 series business switches, Identity Services Engine, IP Phone software, Email Security Appliance (ESA), DNA Center, and Orbital.

Cisco has released patches for these vulnerabilities and says it is not aware of exploits for them being publicly disclosed. Additional details on the resolved issues can be found on Cisco’s security portal.

Related: Cisco Patches Critical Vulnerabilities in IOS XE Software

Related: Cisco Patches High-Severity Security Flaws in IOS XR

Related: Cisco Patches Critical Enterprise NFVIS Vulnerability for Which PoC Exploit Is Available

view counter

Ionut Arghire is an international correspondent for SecurityWeek.

Previous Columns by Ionut Arghire:
Tags:

http://feedproxy.google.com/~r/securityweek/~3/9dldXjEtfMA/cisco-patches-high-severity-vulnerabilities-security-appliances-business-switches




Medtronic Recalls Medical Devices Due to Security Risks That Can Lead to Injury, Death

Medical device maker Medtronic is recalling remote controllers used with some of its insulin pumps due to cybersecurity risks that could lead to injury and even death.

The recall is related to a series of vulnerabilities discovered by a team of cybersecurity researchers in 2018. In June 2019, the U.S. Food and Drug Administration (FDA) and Medtronic informed the public of a recall of MiniMed 508 and Paradigm series insulin pumps due to vulnerabilities that could allow an attacker to remotely hack the devices.

The FDA and Medtronic said that some affected users — whose devices were under warranty — were notified as early as August 2018.

That recall is now being expanded by Medtronic to the optional remote controllers associated with the affected insulin pumps. Users of these devices have been sent updated instructions, including for stopping the use of impacted controllers and returning them.

The FDA said more than 31,000 devices have been recalled in the United States. The agency and Medtronic noted that the affected MiniMed MMT-500 and MMT-503 controllers are no longer manufactured or distributed.

Medtronic remote controllers recalled due to vulnerabilities

“The FDA has identified this as a Class I recall, the most serious type of recall. Use of these devices may cause serious injuries or death,” the FDA said.

However, both the FDA and Medtronic pointed out that they are not aware of any reports of patient harm related to the vulnerabilities.

The cybersecurity flaws discovered by researchers in these devices are related to the wireless communications between the remote controller and the insulin pump. The controller enables users to program the amount of insulin being delivered to the patient.

An attacker in close proximity of the target can intercept the radio frequency signals between the remote controller and the insulin pump and replay them at a later time to either deliver an additional dose of insulin or prevent the delivery of insulin.

“Using specialized equipment, an unauthorized person could instruct the pump to either over-deliver insulin to a patient, leading to low blood sugar (hypoglycemia), or stop insulin delivery, leading to high blood sugar and diabetic ketoacidosis, even death,” the FDA explained.

While the risks posed by these vulnerabilities could be serious, attacks can only be launched under certain conditions. For an attack to work, the victim must enable the remote option for the pump, register the remote controller to the pump, and have a feature named “Easy Bolus” enabled. In addition, the attacker needs to be in close proximity to the victim, and the victim would need to ignore the alerts from the pump indicating that a remote bolus is being delivered.

Nevertheless, Medtronic “has determined that the potential risks associated with the MiniMed remote controller outweigh the benefits of its continued use.”

Several cybersecurity advisories have been issued over the past few years for vulnerabilities discovered in Medtronic products. While device manufacturers can quickly provide mitigations for flaws found in their products, delivering patches can be a lengthy process due to the required regulatory approvals.

Related: FDA Warns of Flaws in Medtronic Programmers

Related: DHS Warns of Vulnerabilities in Medtronic Defibrillators

Related: St. Jude Medical Recalls 465,000 Pacemakers Over Security Vulnerabilities

view counter

Eduard Kovacs (@EduardKovacs) is a contributing editor at SecurityWeek. He worked as a high school IT teacher for two years before starting a career in journalism as Softpedia’s security news reporter. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Previous Columns by Eduard Kovacs:
Tags:

http://feedproxy.google.com/~r/securityweek/~3/jsEInDpQEKg/medtronic-recalls-medical-devices-due-security-risks-can-lead-injury-death




DevOps Security Startup Mondoo Scores $15M Investment

Mondoo, a startup that provides security tools for DevOps teams, has raised $15 million in funding ($12 million in a new Series A round, and $3 million from a previously undisclosed seed round).

The Series A funding round was Led by Atomico with participation from a range of high-profile private investors.

Mondoo says it will use the funding to accelerate product development and hire new talent to scale its team.

Founded in 2020, with headquarters in San Francisco and Berlin, Mondoo provide infrastructure developers with risk assessments and insights into hybrid network infrastructure.

In addition to popular cloud services such as Azure, AWS, and Google Cloud, the company’s cloud-native security platform supports Kubernetes clusters (Amazon EKS, Google Kubernetes Engine, and others); Windows, macOS, and Linux machines; and services such as GitHub, GitLab, and Jenkins.

Related: Privacy Engineering Firm Duality Technologies Raises $30 Million

Related: Behavioral Analytics Provider ForMotiv Raises $6 Million

Related: Identity Solutions Provider Saviynt Raises $130 Million

view counter

Ionut Arghire is an international correspondent for SecurityWeek.

Previous Columns by Ionut Arghire:
Tags:

http://feedproxy.google.com/~r/securityweek/~3/ZK9MS09_S4o/devops-security-startup-mondoo-scores-15m-investment




ESET Discovers UEFI Bootkit in Cyber Espionage Campaign

Threat hunters at ESET are training the spotlight on a previously undocumented UEFI bootkit capable of hijacking the EFI System Partition (ESP) to maintain persistence on infected Windows machines.

The ESET discovery is the second real-world UEFI bootkit to be publicly documented in recent weeks, following Kaspersky’s report on a new Windows UEFI bootloader fitted into the FinSpy surveillance spyware product.

According to ESET researchers Anton Cherepanov and Martin Smolar, the malware has evaded detection for almost a decade and was engineered to bypass Windows Driver Signature Enforcement to load its own unsigned driver.

“We traced the roots of this threat back to at least 2012, previously operating as a bootkit for systems with legacy BIOSes,” the research team said, noting that the upgrade to UEFI went unnoticed and undocumented for many years. “The days of UEFI (Unified Extensible Firmware Interface) living in the shadows of the legacy BIOS are gone for good.”

ESET named the threat “ESPecter” and warned it is capable of injecting code to set up command-and-control server connections.

[ READ: FinSpy Surveillance Spyware Fitted With UEFI Bootkit ]

ESET, which sells anti-malware software to corporate customers around the world, said the bootkit was spotted on a compromised machine along with a user-mode client component with keylogging and document-stealing functionalities 

From the ESET report:

By patching the Windows Boot Manager, attackers achieve execution in the early stages of the system boot process, before the operating system is fully loaded. This allows ESPecter to bypass Windows Driver Signature Enforcement (DSE) in order to execute its own unsigned driver at system startup. 

This driver then injects other user-mode components into specific system processes to initiate communication with ESPecter’s C&C server and to allow the attacker to take control of the compromised machine by downloading and running additional malware or executing C&C commands.

The researchers say they were not able to attribute ESPecter to any known threat actor, but noted there were signs of Chinese debug messages in the user-mode client component, a suggestion that an unknown Chinese-speaking threat actor may be behind this campaign.

“After all the years of insignificant changes, those behind ESPecter apparently decided to move their malware from legacy BIOS systems to modern UEFI systems. They decided to achieve this by modifying a legitimate Windows Boot Manager binary (bootmgfw.efi) located on the ESP while supporting multiple Windows versions spanning Windows 7 through Windows 10,” the team said.

[ READ: Russian Cyberspies Use UEFI Rootkit in Attacks ]

The persistence method only works if the Secure Boot feature in Windows is disabled, a reality on older versions of Microsoft’s operating system. 

For Windows OS versions that support Secure Boot, ESET said the attacker could disable the feature via an “evil maid” physical access attack or exploiting additional security vulnerabilities to expand the attack. 

“ESPecter shows that threat actors are relying not only on UEFI firmware implants when it comes to pre-OS persistence and, despite the existing security mechanisms like UEFI Secure Boot, invest their time into creating malware that would be easily blocked by such mechanisms, if enabled and configured correctly,” the researchers said.

Related: FinSpy Surveillance Spyware Fitted With UEFI Bootkit

Related: China-Linked Hackers Used UEFI Malware in Attacks

Related: Meet MBR-ONI, Bootkit Ransomware Used as a Targeted Wiper

Related: Russian Hackers Using Bootkit to Steal Payment Data

view counter

Ryan Naraine is Editor-at-Large at SecurityWeek and host of the popular Security Conversations podcast series. Ryan is a journalist and cybersecurity strategist with more than 20 years experience covering IT security and technology trends. He is a regular speaker at cybersecurity conferences around the world.
Ryan has built security engagement programs at major global brands, including Intel Corp., Bishop Fox and Kaspersky GReAT. He is a co-founder of Threatpost and the global SAS conference series. Ryan’s career as a journalist includes bylines at major technology publications including Ziff Davis eWEEK, CBS Interactive’s ZDNet, PCMag and PC World.
Follow Ryan on Twitter @ryanaraine.

Previous Columns by Ryan Naraine:
Tags:

http://feedproxy.google.com/~r/securityweek/~3/wHS2vNC7l9g/eset-discovers-uefi-bootkit-cyber-espionage-campaign




Hackers Could Disrupt Industrial Processes via Flaws in Widely Used Honeywell DCS

A distributed control system (DCS) product offered by Honeywell is affected by vulnerabilities that could allow malicious actors to disrupt industrial processes.

Researchers at industrial cybersecurity firm Claroty discovered that Honeywell’s Experion Process Knowledge System (PKS) is affected by three types of vulnerabilities. Two of them, CVE-2021-38395 and CVE-2021-38397, have been assigned a severity rating of critical and can allow an attacker to remotely execute arbitrary code on the system or cause a denial of service (DoS) condition.

The third flaw, tracked as CVE-2021-38399 and classified as high severity, is a path traversal issue that can allow an attacker to access files and folders.

Vulnerabilities found in Honeywell DCSThe industrial giant published a security advisory for these vulnerabilities in February, when it informed customers about its plans for releasing patches this year. Some versions of the impacted products, however, will not receive fixes.

In a blog post published on Tuesday, Claroty detailed the vulnerabilities found by its Team82 researchers, as well as their potential impact in real world environments.

The Honeywell Experion PKS product is used by organizations worldwide to control large industrial processes. The DCS leverages controllers that can be programmed using engineering workstation software named Experion PKS Configuration Studio. The logic programmed for a controller is downloaded from the engineering station to the DCS components.

“In the case of the Experion PKS, Team82 found that it is possible to mimic the download code procedure and use these requests to upload arbitrary DLL/ELF files (for simulators and controllers, respectively). The device then loads the executables without performing checks or sanitization, giving an attacker the ability to upload executables and run unauthorized native code remotely without authentication,” Claroty explained.

Learn more about vulnerabilities in industrial systems at SecurityWeek’s ICS Cyber Security Conference and SecurityWeek’s Security Summits virtual event series

An attacker could exploit the vulnerabilities to cause significant disruptions or to abuse the DCS for further attacks on the targeted organization’s network. However, Claroty pointed out that the ports an attacker needs access to in order to exploit the vulnerabilities are typically not exposed to the internet. The attacker would need to find a way to access the targeted organization’s OT network before exploiting the flaws.

Honeywell said the vulnerabilities impact its C200, C200E, C300 and ACE controllers. The ACE and C200 controllers will not receive patches, but mitigations are available, especially since network access is required for exploitation.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday released both an advisory and a notification to inform organizations about the threat posed by these vulnerabilities.

ICS Cyber Security Conference

Related: Vulnerabilities Allow Hackers to Access Honeywell Fire Alarm Systems

Related: Serious Vulnerabilities Expose Honeywell Surveillance Systems to Attacks

view counter

Eduard Kovacs (@EduardKovacs) is a contributing editor at SecurityWeek. He worked as a high school IT teacher for two years before starting a career in journalism as Softpedia’s security news reporter. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Previous Columns by Eduard Kovacs:
Tags:

http://feedproxy.google.com/~r/securityweek/~3/lD1lZVB52Xs/hackers-could-disrupt-industrial-processes-flaws-widely-used-honeywell-dcs




McAfee Enterprise, FireEye Products Merged Into $2B Entity

Private equity giant Symphony Technology Group (STG) this week announced the merger of McAfee Enterprise and the newly acquired FireEye Products into a single entity with $2 billion in annual revenue.

The Menlo Park, Calif.-based STG has tapped FireEye’s Bryan Palma to head up the combined entity, which will continue to sell security products for endpoints, infrastructure, applications, and cloud deployments.

The STG announcement is the latest chapter in McAfee’s bumpy corporate saga. In March this year, McAfee Corp sold off the McAfee Enterprise business to a consortium led by STG in an all-cash transaction valued at $4 billion.

FireEye Products was purchased by STG in June this year for $1.2 billion after Mandiant decided to split off its solutions unit from the endpoint protection and cloud security product side of the house.

Symphony Technology Group also counts RSA Security among its high-profile portfolio companies.

In a brief statement, STG said the combination of McAfee Enterprise and FireEye Products will immediately create a pure play cybersecurity vendor more than 40,000 customers, 5,000 employees, and nearly $2 billion in annual revenue. 

Related: McAfee Sheds Enterprise Business in $4 Billion Deal

Related: FireEye, Mandiant Split Apart in $1.2B Private Equity Deal

view counter

Previous Columns by SecurityWeek News:
Tags:

http://feedproxy.google.com/~r/securityweek/~3/TzZIOQiUIKc/mcafee-enterprise-fireeye-products-merged-2b-entity




Google Patches Two More Exploited Zero-Day Vulnerabilities in Chrome

Google on Thursday announced the rollout of a Chrome update to address four security vulnerabilities, including two that are already being exploited in the wild.

The exploited vulnerabilities include CVE-2021-37975, a high-severity use-after-free bug in the V8 engine, and CVE-2021-37976, a medium-severity information leak issue in the core. Both were reported last week.

“Google is aware the exploits for CVE-2021-37975 and CVE-2021-37976 exist in the wild,” the Internet search giant says.

Now rolling out to Windows, Mac and Linux users as Chrome version 94.0.4606.71, the new browser iteration also addresses CVE-2021-37974, a high-severity use-after-free in Safe Browsing.

Google says the report for this vulnerability earned the reporting researcher, namely Weipeng Jiang from Codesafe Team of Legendsec at Qi’anxin Group, a $20,000 bug bounty reward.

Exploitation of these vulnerabilities may lead to the execution of arbitrary code in the context of the browser, the Multi-State Information Sharing and Analysis Center (MS-ISAC) warns in an advisory. Successful exploitation may potentially lead to system compromise.

The update comes roughly one week after Google issued an emergency patch for CVE-2021-37973, a high-severity use-after-free issue in the Portals API that was already being exploited in attacks.

With CVE-2021-37975 and CVE-2021-37976, the number of documented zero-day attacks so far in 2021 has been rounded up to 70. Of these, 14 security flaws were found in Google’s Chrome and Android platforms, data reviewed by SecurityWeek shows.

Related: Google Working on Improving Memory Safety in Chrome

Related: Google Warns of Exploited Zero-Days in Chrome Browser

Related: Google Awards Over $130,000 for Flaws Patched With Release of Chrome 93

view counter

Ionut Arghire is an international correspondent for SecurityWeek.

Previous Columns by Ionut Arghire:
Tags:

http://feedproxy.google.com/~r/securityweek/~3/AREBtMqEkEg/google-patches-two-more-exploited-zero-day-vulnerabilities-chrome