{"id":18583,"date":"2021-02-05T19:37:00","date_gmt":"2021-02-05T18:37:00","guid":{"rendered":"http:\/\/159.69.82.204\/win\/?p=18583"},"modified":"2022-12-15T07:25:27","modified_gmt":"2022-12-15T06:25:27","slug":"chrome-88-0-4324-150-fixt-eine-kritische-und-edge-88-0-705-62-sieben-schwachstellen-0-day-im-ie","status":"publish","type":"post","link":"https:\/\/borncity.com\/win\/2021\/02\/05\/chrome-88-0-4324-150-fixt-eine-kritische-und-edge-88-0-705-62-sieben-schwachstellen-0-day-im-ie\/","title":{"rendered":"Chrome 88.0.4324.150 fixes one critical and Edge 88.0.705.62 seven vulnerabilities, 0-day in IE"},"content":{"rendered":"<p><img decoding=\"async\" style=\"float: left; margin: 0px 10px 0px 0px; display: inline;\" src=\"https:\/\/www.borncity.com\/blog\/wp-content\/uploads\/2015\/01\/Chrome.jpg\" align=\"left\" \/>[<a href=\"https:\/\/www.borncity.com\/blog\/2021\/02\/05\/chrome-88-0-4324-150-fixt-eine-kritische-und-edge-88-0-705-62-sieben-schwachstellen-0-day-im-ie\/\" target=\"_blank\" rel=\"noopener\">German<\/a>]Google developers have updated the Chrome browser to version 88.0.4324.150 as of February 4, 2021 in the desktop version for Linux, macOS and Windows. This security update fixes a critical vulnerability in the older browser versions. Microsoft has also released Edge 88.0.705.62, which fixes seven vulnerabilities. And Internet Explorer also has a 0-day vulnerability. Addendum: An update to Edge 88.0.705.63 is available since Feb. 5, 2021.<\/p>\n<p><!--more--><\/p>\n<h2>Chrome 88.0.4324.150\u00a0 fixes a critical vulnerability<\/h2>\n<p><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/vg04.met.vgwort.de\/na\/d6da029baf6f48c3a2e8cc05129c0e8f\" alt=\"\" width=\"1\" height=\"1\" \/>The Google blog has <a href=\"https:\/\/chromereleases.googleblog.com\/2021\/02\/stable-channel-update-for-desktop_4.html\" target=\"_blank\" rel=\"noopener\">this post<\/a> on Chrome 88.0.4324.150, which states a closed vulnerability for the desktop:<\/p>\n<blockquote><p>[$TBD][1170176] High CVE-2021-21148: Heap buffer overflow in V8. Reported by Mattias Buelens on 2021-01-24<\/p><\/blockquote>\n<p>Google is aware of reports that an exploit for CVE-2021-21148 exists in the wild. So the browser should be updated quickly. The Chrome build for Windows, Mac and Linux will be rolled out to systems via the automatic update feature over the next few days. However, you can also <a href=\"https:\/\/www.google.com\/chrome\/\" target=\"_blank\" rel=\"noopener\">download this build here<\/a>.<\/p>\n<blockquote><p>ZDNet points out in <a href=\"https:\/\/www.zdnet.com\/article\/google-patches-an-actively-exploited-chrome-zero-day\/\" target=\"_blank\" rel=\"noopener\">this article<\/a> that North Korean hackers are believed to have attacked security researchers via a 0-day vulnerability in Google Chrome. Microsoft has published <a href=\"https:\/\/www.microsoft.com\/security\/blog\/2021\/01\/28\/zinc-attacks-against-security-researchers\/\" target=\"_blank\" rel=\"noopener\">this article<\/a> about it.<\/p><\/blockquote>\n<h2>0-day vulnerability in Internet Explorer<\/h2>\n<p>In addition, there is a <a href=\"https:\/\/web.archive.org\/web\/20220822074658\/https:\/\/enki.co.kr\/blog\/2021\/02\/04\/ie_0day.html\" target=\"_blank\" rel=\"noopener\">Korean article<\/a> in which security researchers announce a discovered 0-day vulnerability in Internet Explorer, which is also used for such attacks. Bleeping Computer has <a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/hacking-group-also-used-an-ie-zero-day-against-security-researchers\/\" target=\"_blank\" rel=\"noopener\">this post<\/a> on the topic. So far Microsoft has not announced anything regarding an update.<\/p>\n<h2>Edge 88.0.705.62 fixes seven vulnerabilities<\/h2>\n<p>As of February 4, 2021, Microsoft has updated the Chromium-based Edge browser to version 88.0.705.62. This version is based on Chrome 88.0.4324.146, according to <a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2021-21144\" target=\"_blank\" rel=\"noopener\">this MS page<\/a>. This is a security update that fixes seven vulnerabilities, according to <a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\" target=\"_blank\" rel=\"noopener\">this Microsoft security page<\/a>.<\/p>\n<ul>\n<li><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2021-24113\" target=\"_blank\" rel=\"noopener\">CVE-2021-24113<\/a>: (HTML-based) Security Feature Bypass Vulnerability<\/li>\n<li><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2021-21143\" target=\"_blank\" rel=\"noopener\">CVE-2021-21143<\/a>: Heap buffer overflow in Extensions<\/li>\n<li><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2021-21142\" target=\"_blank\" rel=\"noopener\">CVE-2021-21142<\/a>: Use after free in Payments<\/li>\n<li><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2021-21144\" target=\"_blank\" rel=\"noopener\">CVE-2021-21144<\/a>: Heap buffer overflow in Tab Groups<\/li>\n<li><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2021-21145\" target=\"_blank\" rel=\"noopener\">CVE-2021-21145<\/a>: Use after free in Fonts<\/li>\n<li><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2021-21146\" target=\"_blank\" rel=\"noopener\">CVE-2021-21146<\/a> : Use after free in Navigation<\/li>\n<li><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2021-21147\" target=\"_blank\" rel=\"noopener\">CVE-2021-21147<\/a>: Inappropriate implementation in Skia<\/li>\n<\/ul>\n<p>The browser should be updated automatically.<\/p>\n<h3>Microsoft released\u00a0Edge 88.0.705.63<\/h3>\n<p>Addendum: Microsoft has released Edge 88.0.705.63 on February 5,\u00a0 2021. I received the following advisory this night:<\/p>\n<p>*******************************************************************************<br \/>\nTitle: Microsoft Security Update Releases<br \/>\nIssued: February 5, 2021<br \/>\n*******************************************************************************<br \/>\nSummary<br \/>\n=======<\/p>\n<p>The following CVEs have been released on February 4, 2021.<\/p>\n<p>* CVE-2021-24113<\/p>\n<p>&#8211; CVE-2021-24113 | Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability<br \/>\n&#8211; https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2021-24113<br \/>\n&#8211; Version 1.0<br \/>\n&#8211; Reason for Revision: Information published.<br \/>\n&#8211; Originally posted: February 4, 2021<br \/>\n&#8211; Updated: N\/A<br \/>\n&#8211; Aggregate CVE Severity Rating: Important<\/p>\n<p>The following CVEs released on February 4, 2021 and February 5, 2021 were assigned by Chrome. Microsoft Edge<br \/>\n(Chromium-based) ingests Chromium, which addresses these vulnerabilities. Please see<br \/>\nGoogle Chrome Releases (https:\/\/chromereleases.googleblog.com\/2021) for more information.<\/p>\n<p>See<br \/>\nhttps:\/\/msrc-blog.microsoft.com\/2021\/01\/13\/security-update-guide-supports-cves-assigned-by-industry-partners\/<br \/>\nfor more information about third-party CVEs in the Security Update Guide.<\/p>\n<p>* CVE-2021-21148<\/p>\n<p>Revision Information:<br \/>\n=====================<\/p>\n<p>&#8211; Version 1.0<br \/>\n&#8211; Reason for Revision: Information published.<br \/>\n&#8211; Originally posted: February 5, 2021<\/p>\n<p>* CVE-2021-21142<br \/>\n* CVE-2021-21143<br \/>\n* CVE-2021-21144<br \/>\n* CVE-2021-21145<br \/>\n* CVE-2021-21146<br \/>\n* CVE-2021-21147<\/p>\n<p>Revision Information:<br \/>\n=====================<\/p>\n<p>&#8211; Version 1.0<br \/>\n&#8211; Reason for Revision: Information published.<br \/>\n&#8211; Originally posted: February 4, 2021<\/p>\n","protected":false},"excerpt":{"rendered":"<p>[German]Google developers have updated the Chrome browser to version 88.0.4324.150 as of February 4, 2021 in the desktop version for Linux, macOS and Windows. This security update fixes a critical vulnerability in the older browser versions. Microsoft has also released &hellip; <a href=\"https:\/\/borncity.com\/win\/2021\/02\/05\/chrome-88-0-4324-150-fixt-eine-kritische-und-edge-88-0-705-62-sieben-schwachstellen-0-day-im-ie\/\">Continue reading <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[872,580,22],"tags":[780,69,195],"class_list":["post-18583","post","type-post","status-publish","format-standard","hentry","category-browser","category-security","category-update","tag-chrome","tag-security","tag-update"],"_links":{"self":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts\/18583","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/comments?post=18583"}],"version-history":[{"count":0,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts\/18583\/revisions"}],"wp:attachment":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/media?parent=18583"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/categories?post=18583"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/tags?post=18583"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}