Cyber999 Advisories

1 April 2024     Advisory

MA-1054.042024: MyCERT Advisory - Security Updates-Google Chrome Browser


1.0 Introduction
Google has released security updates to address multiple vulnerabilities in the Chrome browser. This security update addresses 7 security vulnerabilities, including the following critical and high severity issues.

2.0 Impact
Allows the attackers to remotely execute malicious code on a victim’s machine or compromise sensitive data.

  • Critical (CVE-2024-2883): A use-after-free vulnerability in ANGLE.
  • High (CVE-2024-2885): A use-after-free vulnerability in Dawn.
  • High (CVE-2024-2886): A use-after-free vulnerability in WebCodecs.
  • High (CVE-2024-2887): A type confusion vulnerability in WebAssembly.


3.0 Affected Products
The affected Chrome browsers are:

  • Google Chrome for Windows, Mac, Linux, and Android.


4.0 Recommendations
Users are recommended to update to version 120.0.6099.129 for macOS and Linux and 120.0.6099.129/130 for Windows to mitigate potential threats. Users are also encouraged to enable the automatic update function in Chrome to ensure that their software is updated promptly.

Users and system administrators are encouraged to review the Google Chrome security update and upgrade to the latest version.

Fixed versions:

  • Stable Channel Update for Desktop
    • Chrome 123.0.6312.86/.87 for Windows and Mac.
    • Chrome 123.0.6312.86 for Linux.
  • Extended Stable Channel Update for Desktop
    • Chrome 122.0.6261.148 for Windows and Mac.
  • Chrome 123 (123.0.6312.80) for Android

Generally, CyberSecurity Malaysia advises the users to be updated with the latest security announcements by the vendor and follow best practice security policies to determine which updates should be applied.

For further enquiries, please contact us through the following channels:

E-mail: cyber999[at]cybersecurity.my 
Phone: 1-300-88-2999 (monitored during business hours) 
Mobile: +60 19 2665850 (24x7 call incident reporting) 
Business Hours: Mon - Fri 08:30 -17:30 MYT 
Web: https://www.mycert.org.my 
Twitter: https://twitter.com/mycert 
Facebook: https://www.facebook.com/mycert.org.my

5.0    References

logo
CyberSecurity Malaysia is the national cyber security specialist agency under the purview of the Ministry of Digital (KD)
 
Contact Us

  • CyberSecurity Malaysia,
    Level 7 Tower 1, Menara Cyber Axis, Jalan Impact,
    63000 Cyberjaya, Selangor Darul Ehsan, Malaysia.

  • info@cybersecurity.my

  • +603 - 8800 7999

  • +603 - 8008 7000

TOP
ASK Byte
Chatbot Portal

Hi, I am ASK Byte. Please submit your questions about the portal and I will try to get answers from online knowledge stores.

Hi, Saya Admin Chatbot. Saya sedia chat dengan anda secara terus. Bagaimana saya boleh membantu anda?

Click the button below to interact with the CSM chatbot

Proceed