• Nasty zero-day in Chrome

    From Andrew@21:1/5 to All on Sat May 11 23:06:08 2024
    https://www.zdnet.com/article/update-your-chrome-browser-asap-google-has-confirmed-a-zero-day-exploited-in-the-wild/

    Discovered by an anonymous researcher and reported directly to Google, CVE-2024-4671 has a Common Vulnerability Scoring System (CVSS) rating of
    8.8, which means it's a serious vulnerability.

    --- SoupGate-Win32 v1.05
    * Origin: fsxNet Usenet Gateway (21:1/5)
  • From Newyana2@21:1/5 to Andrew on Sat May 11 20:55:41 2024
    On 5/11/2024 7:06 PM, Andrew wrote:
    https://www.zdnet.com/article/update-your-chrome-browser-asap-google-has-confirmed-a-zero-day-exploited-in-the-wild/

    Discovered by an anonymous researcher and reported directly to Google, CVE-2024-4671 has a Common Vulnerability Scoring System (CVSS) rating of
    8.8, which means it's a serious vulnerability.


    It sounds like it will work to disable the V-8 optimizer in
    privacy settings, which is a good idea, anyway.

    --- SoupGate-Win32 v1.05
    * Origin: fsxNet Usenet Gateway (21:1/5)
  • From Brian Gregory@21:1/5 to Andrew on Sun May 12 16:37:59 2024
    On 12/05/2024 00:06, Andrew wrote:
    https://www.zdnet.com/article/update-your-chrome-browser-asap-google-has-confirmed-a-zero-day-exploited-in-the-wild/

    Discovered by an anonymous researcher and reported directly to Google, CVE-2024-4671 has a Common Vulnerability Scoring System (CVSS) rating of
    8.8, which means it's a serious vulnerability.

    My Chrome has already updated itself twice since then.

    --
    Brian Gregory (in England).

    --- SoupGate-Win32 v1.05
    * Origin: fsxNet Usenet Gateway (21:1/5)
  • From micky@21:1/5 to ...winston on Sun May 12 18:56:16 2024
    In alt.comp.os.windows-10, on Sun, 12 May 2024 12:27:40 -0400,
    "...winston" <winstonmvp@gmail.com> wrote:

    Brian Gregory wrote:
    On 12/05/2024 00:06, Andrew wrote:
    https://www.zdnet.com/article/update-your-chrome-browser-asap-google-has-confirmed-a-zero-day-exploited-in-the-wild/


    Discovered by an anonymous researcher and reported directly to Google,
    CVE-2024-4671 has a Common Vulnerability Scoring System (CVSS) rating of >>> 8.8, which means it's a serious vulnerability.

    My Chrome has already updated itself twice since then.


    Your version when using Windows if updated twice, had to be two versions >older than 124.6367.170 which was the version that pre-dated the current >124.6367.202(or x.201 for Enterprise)

    Just now I had version .....201 until I went to ..., help, about and
    then it started updating instantaneously.

    The laptop computer within winHome had v.158!! Now why did it have such
    an old one? But it started updating immediately also, after I went to
    About.

    Both needed relaunching of course to actually update.

    The version x.202(x.201) was released three days ago(May 9th)

    Note: Enterprise auto-updating is staged(days/weeks).

    Now they are both 202. Thanks Andrew, et al.

    --- SoupGate-Win32 v1.05
    * Origin: fsxNet Usenet Gateway (21:1/5)
  • From Paul@21:1/5 to micky on Mon May 13 00:46:50 2024
    On 5/12/2024 6:56 PM, micky wrote:
    In alt.comp.os.windows-10, on Sun, 12 May 2024 12:27:40 -0400,
    "...winston" <winstonmvp@gmail.com> wrote:

    Brian Gregory wrote:
    On 12/05/2024 00:06, Andrew wrote:
    https://www.zdnet.com/article/update-your-chrome-browser-asap-google-has-confirmed-a-zero-day-exploited-in-the-wild/


    Discovered by an anonymous researcher and reported directly to Google, >>>> CVE-2024-4671 has a Common Vulnerability Scoring System (CVSS) rating of >>>> 8.8, which means it's a serious vulnerability.

    My Chrome has already updated itself twice since then.


    Your version when using Windows if updated twice, had to be two versions
    older than 124.6367.170 which was the version that pre-dated the current
    124.6367.202(or x.201 for Enterprise)

    Just now I had version .....201 until I went to ..., help, about and
    then it started updating instantaneously.

    The laptop computer within winHome had v.158!! Now why did it have such
    an old one? But it started updating immediately also, after I went to
    About.

    Both needed relaunching of course to actually update.

    The version x.202(x.201) was released three days ago(May 9th)

    Note: Enterprise auto-updating is staged(days/weeks).

    Now they are both 202. Thanks Andrew, et al.


    Maybe you "did one of those recipes" ?

    https://stackoverflow.com/questions/71268342/disable-google-chrome-auto-update-in-windows-11

    Paul

    --- SoupGate-Win32 v1.05
    * Origin: fsxNet Usenet Gateway (21:1/5)
  • From micky@21:1/5 to nospam@needed.invalid on Sun May 26 06:59:22 2024
    In alt.comp.os.windows-10, on Mon, 13 May 2024 00:46:50 -0400, Paul <nospam@needed.invalid> wrote:

    On 5/12/2024 6:56 PM, micky wrote:
    In alt.comp.os.windows-10, on Sun, 12 May 2024 12:27:40 -0400,
    "...winston" <winstonmvp@gmail.com> wrote:

    Brian Gregory wrote:
    On 12/05/2024 00:06, Andrew wrote:
    https://www.zdnet.com/article/update-your-chrome-browser-asap-google-has-confirmed-a-zero-day-exploited-in-the-wild/


    Discovered by an anonymous researcher and reported directly to Google, >>>>> CVE-2024-4671 has a Common Vulnerability Scoring System (CVSS) rating of >>>>> 8.8, which means it's a serious vulnerability.

    My Chrome has already updated itself twice since then.


    Your version when using Windows if updated twice, had to be two versions >>> older than 124.6367.170 which was the version that pre-dated the current >>> 124.6367.202(or x.201 for Enterprise)

    Just now I had version .....201 until I went to ..., help, about and
    then it started updating instantaneously.

    The laptop computer within winHome had v.158!! Now why did it have such
    an old one? But it started updating immediately also, after I went to
    About.

    Both needed relaunching of course to actually update.

    The version x.202(x.201) was released three days ago(May 9th)

    Note: Enterprise auto-updating is staged(days/weeks).

    Now they are both 202. Thanks Andrew, et al.


    Maybe you "did one of those recipes" ?

    https://stackoverflow.com/questions/71268342/disable-google-chrome-auto-update-in-windows-11

    Paul

    I don't think so. I normally just ignore Chrome.

    --- SoupGate-Win32 v1.05
    * Origin: fsxNet Usenet Gateway (21:1/5)