Connect with us

Tech

Chrome 151 Patches 370 Vulnerabilities, 7 Critical

Published

on

Google has just reminded everyone how enormous Chrome’s attack surface can be, rolling out fixes for 370 security flaws in a single browser update.

Chrome version 151 arrives with patches affecting core browser technologies, several of which contain memory-safety bugs that can lead to browser crashes or arbitrary code execution.

Although Google has not reported active exploitation, vulnerabilities affecting these components typically receive close attention from security researchers because they sit deep inside the browser’s architecture.

The release also illustrates how browser security has shifted from reacting to attacks toward preventing them before they emerge. Many of the vulnerabilities were uncovered through Google’s internal testing and security research programs rather than through public incidents, allowing the company to close hundreds of weaknesses before they became broader security problems.

Use-after-free bugs dominate Chrome’s latest security update

Of the 370 vulnerabilities Google addressed in Chrome 151, seven were rated Critical, 71 High, 170 Medium, and 122 Low, according to Inforsecurity Magazine. The update spans nearly every layer of the browser, including Chrome’s update mechanism.

Among the fixes, use-after-free bugs appeared repeatedly. Google patched four Critical vulnerabilities affecting the Compositing, Views, Skia, and Ozone components, all stemming from a class of memory-safety flaws.

A use-after-free bug occurs when software continues to access memory after it has been freed, creating opportunities for memory corruption that, under certain conditions, could allow an attacker to crash the browser or execute arbitrary code.

The remaining Critical vulnerabilities involved insufficient validation of untrusted input in the Dawn and ANGLE components, as well as a race condition in Chrome’s updater.

The High, Medium, and Low severity fixes covered a broad range of browser subsystems, including Navigation, PDF, Downloads, Password Manager, Site Isolation, Audio, and Chrome Enterprise.

Many of these vulnerabilities fell into familiar categories such as type confusion, integer overflow, out-of-bounds memory access, and policy bypasses. These are bug classes that security researchers often examine because they can sometimes be chained together to bypass browser defenses.

Must-read security coverage

In its announcement, Chrome thanked security researchers who helped flag security flaws, preventing them from reaching production code.

Google said many Chrome security bugs are detected using automated tools, including AddressSanitizer, MemorySanitizer, UndefinedBehaviorSanitizer, Control Flow Integrity, libFuzzer, and AFL.

While these tools are not AI-powered, their growing use in software development and testing underscores their importance and points to the future of vulnerability testing. That same path has recently become actively favored by Microsoft, which recently discovered a record-breaking number of vulnerabilities on its last Patch Tuesday update using AI.

What can users do now?

For Chrome users, the most important task is to ensure their browser is up to date. Chrome usually downloads updates automatically, but users must relaunch the browser to apply them. Because browser vulnerabilities can be severe, it is still worth checking manually.

To do so, type chrome://version in your browser; if it shows 151.xxx, it is up to date. The update applies to Windows, macOS users, and Linux

Google Chrome update screen.
Image: Screenshot from Chrome

The company also noted that it has withheld technical details about several vulnerabilities until most users have installed the update, to reduce the risk of attackers leveraging published exploits to attack users, as we’ve seen recently.

>

Continue Reading

Tech

Planned Amazon data center could become the biggest climate polluter in the U.S.

Published

on

As part of a planned data center in Pecos County, Texas, Amazon is investing in an on-site power plant that could become the largest source of climate pollution in the United States, according to The New York Times.

The NYT says the plant would burn natural gas and is permitted to release 33 million tons of carbon dioxide per year — more than any other power plant in the U.S.

In a statement, an Amazon spokesperson confirmed that the data center will “be powered by new on-site generation that won’t raise electricity costs for Texas families.” (Data centers face growing political opposition for a number of reasons, including their effect on electricity costs.)

AI has already had a significant impact on Amazon’s carbon emissions, which it reported were up 16% last year — the wrong direction for a company that pledged to eliminate its carbon emissions by 2040. And that could get worse as Amazon and tech companies back the development of huge natural gas plants to support their power-hungry data centers.

The Amazon spokesperson said, “The world looks different now than when we co-founded the climate pledge,” while also claiming, “Our commitment hasn’t changed.”

>

Continue Reading

Tech

OpenAI acquires presentation startup NextSlide

Published

on

NextSlide recently announced that it’s joining OpenAI, with the presentation startup’s team members now working on ChatGPT.

The NextSlide website currently displays a note from founder Ahmed Beshry describing the startup’s product as one “that could turn prompts, notes, documents, or research into a polished, editable presentation.”

The ultimate goal, Beshry said, was “to make visual communication more accessible and help more people express their ideas clearly.” So by joining OpenAI, the team will “continue pursuing that same mission: building AI products that help people create, communicate, and turn their ideas into meaningful work.”

The financial terms of the deal were not disclosed. In a note on LinkedIn, Beshry said the announcement is coming “a few months late,” as the acquisition took place “earlier this year.”

Beshry was previously a co-founder at Caper AI, a smart cart/cashier-less checkout startup acquired by Instacart in 2021.

>

Continue Reading

Tech

X replaces ‘misaligned’ revenue sharing program with Original Content Rewards

Published

on

X, the social media platform now owned by Elon Musk’s SpaceX, is shaking up how it pays influencers and creators.

In announcing the change, the company said it will be winding down its existing Revenue Sharing program and replacing it with something called Original Content Rewards. X will stop accepting new Revenue Sharing participants, while existing participants will continue earning money through September 7.

Then, starting on September 8, they’ll be able to apply for the new program. Participants will still need to subscribe to one of X’s Premium tiers, and there will be qualifying thresholds for follower count (500 verified followers) and impressions (500,000 Home Timeline impressions from verified users in 90 days), but it sounds like the big change is the emphasis on originality. 

What counts as original content? X said it can include original reporting and analysis, photos and videos created by the poster, or memes and graphics they’ve designed themselves. Commentary also counts, but “if your content regularly incorporates material created by others, you’ll need to contribute meaningful original value for it to qualify under our original content guidelines.”

The company also included examples of posts that won’t count as original, such as those just copied over from another account, downloaded from one account and re-uploaded to your own, or reposting content “without meaningful transformation.”

This announcement follows repeated attempts by X to reform the Revenue Sharing program, for example reducing payments to aggregators and “clickbait” accounts in April. But these efforts have also prompted complaints from popular accounts profiting from the current system; Musk even reversed some of those changes (giving a creator’s local audience more weight when calculating payouts) after a backlash.

In a post about the new changes, X’s Allegra Jacchia wrote that the existing program “had reached a point where its incentives were misaligned.”

“Creators should be focused on bringing net new content to the platform instead of maximizing payouts,” she said. “We could have kept adding more rules and exceptions, but ultimately the better decision was to start fresh and build a program designed from day one to reward originality.”

Jacchia added that X be “continue refining the program, improving our models, and raising the bar over time.”

When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.

>

Continue Reading

Trending

Copyright © 2017 Zox News Theme. Theme by MVP Themes, powered by WordPress.