1. Home
  2. >
  3. Technology 🛠️
Posted

Major Browsers Release Critical Security Updates - Update Now to Fix WebP Vulnerability

  • Update Chrome, Firefox, Edge, or Brave browsers now to fix a "critical" security issue.

  • The vulnerability could allow hackers to access or run malicious code on your computer.

  • Browsers should update automatically, but you may need to restart for the update to apply.

  • The issue affects WebP image compression, used by many browsers and apps.

  • Password managers like 1Password have also released updates to address this vulnerability.

cnet.com
Relevant topic timeline:
August has seen a flurry of patches released by technology giants like Microsoft, Google Chrome, and Firefox to fix serious vulnerabilities. These patches are crucial as some of the flaws are already being exploited in attacks. While there was no iPhone update from Apple, major fixes were released for enterprise software, including Ivanti, SAP, and Cisco. Microsoft's Patch Tuesday fixed numerous vulnerabilities, including ones being actively targeted. Google Chrome also issued updates, addressing high impact flaws in V8 and WebRTC. Firefox patched various vulnerabilities, some of which could lead to arbitrary code execution. Lastly, Google patched several critical vulnerabilities in its Android operating system, including RCE issues in System and Media Framework.
Google has released emergency security updates for Chrome to address a zero-day vulnerability (CVE-2023-4863) that has been exploited in attacks, urging users to update their browsers to prevent further exploitation.
Apple has released urgent security updates to patch vulnerabilities actively exploited, including flaws in WebKit, certificate validation, and kernel access, which were part of an exploit chain used to plant the Pegasus and Predator spyware.
Google has resubmitted a disclosure of a critical code-execution vulnerability, originally thought to only affect the Chrome browser, revealing that thousands of apps and software frameworks are affected by the flaw.
Google has released emergency security updates to patch a zero-day vulnerability in Chrome that has been exploited in spyware attacks, with the vulnerability caused by a heap buffer overflow weakness in the VP8 encoding of the libvpx video codec library.
Google has released an emergency patch for a zero-day vulnerability in Chrome that was exploited by a commercial spyware vendor, and the vulnerability has been linked to the zero-click iMessage exploit chain used to deploy the NSO Group's Pegasus spyware on compromised iPhones.
A critical zero-day vulnerability in Google Chrome and Mozilla Firefox exposes the internet to potential attacks, with the flaw affecting the widely-used libvpx code library for processing media files in the VP8 format.
Microsoft has released patches to address zero-day vulnerabilities in open source libraries that affect its products, such as Skype and Edge browser, but the company has not confirmed if these vulnerabilities were exploited or if they were aware of any exploitation.