* . *
  • About
  • Advertise
  • Privacy & Policy
  • Contact
Sunday, December 7, 2025
Earth-News
  • Home
  • Business
  • Entertainment
    “This acquisition brings together two pioneering entertainment businesses, combining Netflix’s innovation, global reach and best-in-class streaming service with Warner Bros.’ century-long legacy of world-class storytelling.” – facebook.com

    Netflix and Warner Bros. Join Forces to Revolutionize Entertainment with Unmatched Innovation and Legendary Storytelling

    Through the lens: Four decades of arts & entertainment with photojournalist Roger Mastroianni – Fresh Water Cleveland

    Through the lens: Four decades of arts & entertainment with photojournalist Roger Mastroianni – Fresh Water Cleveland

    Discussing Netflix’s deal to buy Warner Bros. – Spectrum News

    Discussing Netflix’s deal to buy Warner Bros. – Spectrum News

    Why Caesars Entertainment (CZR) Stock Is Down Today – Markets Financial Content

    Why Caesars Entertainment (CZR) Stock Took a Hit Today

    12TH ANNUAL WOMEN IN ENTERTAINMENT RETURNS TO DIGNITY HEALTH SPORTS PARK ON DECEMBER 11 – Dignity Health Sports Park

    12th Annual Women in Entertainment Event Makes a Grand Return to Dignity Health Sports Park on December 11

    Gwyneth Paltrow Gives Red Hot Stiletto Trend a Contrast Twist at Women in Entertainment Gala – WWD

    Gwyneth Paltrow Turns Up the Heat with Bold Stiletto Twist at Women in Entertainment Gala

  • General
  • Health
  • News

    Cracking the Code: Why China’s Economic Challenges Aren’t Shaking Markets, Unlike America’s” – Bloomberg

    Trump’s Narrow Window to Spread the Truth About Harris

    Trump’s Narrow Window to Spread the Truth About Harris

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Trending Tags

    • Trump Inauguration
    • United Stated
    • White House
    • Market Stories
    • Election Results
  • Science
  • Sports
  • Technology
    Amundi Acquires 235,432 Shares of Cognizant Technology Solutions Corporation $CTSH – MarketBeat

    Amundi Acquires 235,432 Shares of Cognizant Technology Solutions Corporation $CTSH – MarketBeat

    ComNav unveils innovative products ‘From Earth to Ocean’ – GPS World

    ComNav Launches Revolutionary ‘From Earth to Ocean’ Product Line

    Gorilla Technology (NASDAQ: GRRR) gets 2025 Nobel Sustainability Trust nod for Leadership in Implementation – Stock Titan

    Gorilla Technology (NASDAQ: GRRR) gets 2025 Nobel Sustainability Trust nod for Leadership in Implementation – Stock Titan

    The 65″ Panasonic Z95A 4K OLED TV With MLA Technology Drops to $1,499.99 Only at Best Buy – IGN Southeast Asia

    The 65″ Panasonic Z95A 4K OLED TV With MLA Technology Drops to $1,499.99 Only at Best Buy – IGN Southeast Asia

    Hospitals Under Pressure: How Technology Can Transform Operations – MedCity News

    Hospitals Under Pressure: How Technology Is Transforming Healthcare Operations

    Novidea Global Survey Reveals 73% of Insurance Executives Plan to Change Core Insurance Management Technology Over the Next Three Years – markets.businessinsider.com

    Nearly Three-Quarters of Insurance Executives Plan Major Overhaul of Core Management Technology Within Three Years

    Trending Tags

    • Nintendo Switch
    • CES 2017
    • Playstation 4 Pro
    • Mark Zuckerberg
No Result
View All Result
  • Home
  • Business
  • Entertainment
    “This acquisition brings together two pioneering entertainment businesses, combining Netflix’s innovation, global reach and best-in-class streaming service with Warner Bros.’ century-long legacy of world-class storytelling.” – facebook.com

    Netflix and Warner Bros. Join Forces to Revolutionize Entertainment with Unmatched Innovation and Legendary Storytelling

    Through the lens: Four decades of arts & entertainment with photojournalist Roger Mastroianni – Fresh Water Cleveland

    Through the lens: Four decades of arts & entertainment with photojournalist Roger Mastroianni – Fresh Water Cleveland

    Discussing Netflix’s deal to buy Warner Bros. – Spectrum News

    Discussing Netflix’s deal to buy Warner Bros. – Spectrum News

    Why Caesars Entertainment (CZR) Stock Is Down Today – Markets Financial Content

    Why Caesars Entertainment (CZR) Stock Took a Hit Today

    12TH ANNUAL WOMEN IN ENTERTAINMENT RETURNS TO DIGNITY HEALTH SPORTS PARK ON DECEMBER 11 – Dignity Health Sports Park

    12th Annual Women in Entertainment Event Makes a Grand Return to Dignity Health Sports Park on December 11

    Gwyneth Paltrow Gives Red Hot Stiletto Trend a Contrast Twist at Women in Entertainment Gala – WWD

    Gwyneth Paltrow Turns Up the Heat with Bold Stiletto Twist at Women in Entertainment Gala

  • General
  • Health
  • News

    Cracking the Code: Why China’s Economic Challenges Aren’t Shaking Markets, Unlike America’s” – Bloomberg

    Trump’s Narrow Window to Spread the Truth About Harris

    Trump’s Narrow Window to Spread the Truth About Harris

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Trending Tags

    • Trump Inauguration
    • United Stated
    • White House
    • Market Stories
    • Election Results
  • Science
  • Sports
  • Technology
    Amundi Acquires 235,432 Shares of Cognizant Technology Solutions Corporation $CTSH – MarketBeat

    Amundi Acquires 235,432 Shares of Cognizant Technology Solutions Corporation $CTSH – MarketBeat

    ComNav unveils innovative products ‘From Earth to Ocean’ – GPS World

    ComNav Launches Revolutionary ‘From Earth to Ocean’ Product Line

    Gorilla Technology (NASDAQ: GRRR) gets 2025 Nobel Sustainability Trust nod for Leadership in Implementation – Stock Titan

    Gorilla Technology (NASDAQ: GRRR) gets 2025 Nobel Sustainability Trust nod for Leadership in Implementation – Stock Titan

    The 65″ Panasonic Z95A 4K OLED TV With MLA Technology Drops to $1,499.99 Only at Best Buy – IGN Southeast Asia

    The 65″ Panasonic Z95A 4K OLED TV With MLA Technology Drops to $1,499.99 Only at Best Buy – IGN Southeast Asia

    Hospitals Under Pressure: How Technology Can Transform Operations – MedCity News

    Hospitals Under Pressure: How Technology Is Transforming Healthcare Operations

    Novidea Global Survey Reveals 73% of Insurance Executives Plan to Change Core Insurance Management Technology Over the Next Three Years – markets.businessinsider.com

    Nearly Three-Quarters of Insurance Executives Plan Major Overhaul of Core Management Technology Within Three Years

    Trending Tags

    • Nintendo Switch
    • CES 2017
    • Playstation 4 Pro
    • Mark Zuckerberg
No Result
View All Result
Earth-News
No Result
View All Result
Home Technology

CISA adds latest Chrome zero-day to Known Exploited Vulnerabilities Catalog

October 3, 2023
in Technology
CISA adds latest Chrome zero-day to Known Exploited Vulnerabilities Catalog
Share on FacebookShare on Twitter

The US’s Cybersecurity and Infrastructure Security Agency (CISA) has added the latest actively exploited zero-day vulnerability affecting Google Chrome to its Known Exploited Vulnerabilities (KEV) Catalog.

The bug, tracked as CVE-2023-5217, received a patch from Google last week and was assigned a severity rating of 8.8 on the CVSS v3 scale.

With its addition to the KEV Catalog, CISA has effectively indicated that exploits for the vulnerability pose a “significant risk to the federal enterprise,” and agencies in the Federal Civilian Executive Branch (FCEB) have been set a three-week deadline of October 23 to apply the recommended fixes.

The vulnerability itself is a heap buffer overflow vulnerability affecting VP8 encoding in libvpx, an open source video codec library from the WebM Project.

Google hasn’t released many details regarding the vulnerability or the exploit chain, saying the restriction to information will remain until the majority of its users have updated to the safe version of Chrome.

Details will also continue to be withheld if the vulnerability continues to impact a third-party library on which other projects depend.

However, the public has been told the vulnerability can be exploited using a specially crafted HTML page and VP8 media stream to exploit heap corruption.

A software’s heap is one of the most common targets for cyber criminals looking to develop exploits for popular applications, along with the stack.

Such exploits can often lead to crashes or the execution of arbitrary code on a victim’s machine, and the prevalence of Google Chrome throughout the world underlines the seriousness with which vulnerabilities like these should be taken, especially in the context of government-level IT.

“These types of vulnerabilities are frequent attack vectors for malicious cyber actors and pose significant risks to the federal enterprise,” CISA said in its alert.

Patch now

Although the mitigation deadlines outlined in the KEV Catalog apply only to FCEB agencies, CISA urged all organizations to apply the recommended fixes in a “timely” way. 

“CISA will continue to add vulnerabilities to the Catalog that meet the specified criteria,” it added.

Google’s advisory instructed users to apply its stable channel update for Windows, Mac, and Linux – version 117.0.5938.132 – which will be made available “over the coming days and weeks”.

The scope of the vulnerability is wider than only Google Chrome, just as it was originally thought. 

Arch Linux provided a list of the 29 open source packages that require libvpx.

Microsoft’s advisory indicated that its Chromium-based Edge browser was originally vulnerable to the bug too, but has been secured in the latest stable and extended stable versions, 117.0.2045.47 and 116.0.1938.98 respectively.

It additionally revealed that “certain versions” of Microsoft Teams and Skype are also vulnerable to CVE-2023-5217, saying “Microsoft is working to identify and address this vulnerability as soon as possible.”

Debian has released security updates for its oldstable (bullseye) and stable (bookworm). Users should upgrade to versions 1.9.0-1+deb11u1 and 1.12.0-1+deb12u1 respectively to secure against CVE-2023-5217.

Chrome’s zero-day woes

Google has been busily patching zero-days in Chrome throughout September, including a similar-looking vulnerability at the start of the month, tracked as CVE-2023-4863.

Like the latest one added to CISA’s KEV Catalog, this was also a heap buffer overflow issue but affected a different open source library, libwebp, one developed by Google to encode and decode WebP images. 

In case there was any doubt about using legacy Edge, Microsoft 365 throws its weight behind WebView2

New VS Code release hits stable channel for everyone who’s not on Apple Silicon after last-minute bug found

Chrome zero-day bug that is actively being abused by bad folks affects Edge, Vivaldi, and other Chromium-tinged browsers

Security researchers believe mass exploitation attempts against WS_FTP have begun

It too was patched quickly and received an identically high severity score of 8.8, in part due to it also being actively exploited at the time patches were released.

CISA added CVE-2023-4863 to its KEV Catalog as well, the deadline to apply the patches was set for October 4.

The full attack surface for the bug isn’t fully uderstood, but libwebp is popular among major browsers and according to Tenable, Firefox, Thunderbird, Microsoft Edge, Opera, and Brave were all vulnerable.

The Electron framework also includes libwebp, meaning applications like 1Password and 3CX desktop were affected too, Tenable said.

A full list of affected Electron-based software is being collated by Michael Taggart on GitHub. ®

>>> Read full article>>>
Copyright for syndicated content belongs to the linked Source : The Register – https://go.theregister.com/feed/www.theregister.com/2023/10/03/cisa_adds_latest_chrome_zeroday/

Tags: Chromelatesttechnology
Previous Post

Microsoft kills its classic Azure DaaS, because it isn’t really Azure

Next Post

5G satellite briefly becomes brightest object in night sky

Argentina drawn in 2026 World Cup Group J: What to know about Algeria, Austria, Jordan – The Athletic – The New York Times

Argentina drawn in 2026 World Cup Group J: What to know about Algeria, Austria, Jordan – The Athletic – The New York Times

December 7, 2025
CEO of U.S. Bancorp weighs in on the economy, tariffs and AI – MPR News

U.S. Bancorp CEO Reveals Surprising Insights on the Economy, Tariffs, and the Future of AI

December 7, 2025
“This acquisition brings together two pioneering entertainment businesses, combining Netflix’s innovation, global reach and best-in-class streaming service with Warner Bros.’ century-long legacy of world-class storytelling.” – facebook.com

Netflix and Warner Bros. Join Forces to Revolutionize Entertainment with Unmatched Innovation and Legendary Storytelling

December 7, 2025
Schumer says Democrats will bring up bill to extend health care tax credits for 3 years – CBS News

Schumer Unveils Bold Plan to Extend Health Care Tax Credits for Three More Years

December 7, 2025
National Park Service overhauls free admission days to include Trump’s birthday – CNN

National Park Service Revamps Free Admission Days to Celebrate Trump’s Birthday

December 7, 2025
Fangnuozhai rainforest ecological manor, Hainan’s natural oxygen bar – news.cgtn.com

Explore Fangnuozhai Rainforest Ecological Manor: Hainan’s Ultimate Natural Oxygen Haven

December 6, 2025
Computer Science Major Discusses Learning How to Navigate Motivation in College – University of New Haven

Computer Science Major Discusses Learning How to Navigate Motivation in College – University of New Haven

December 6, 2025
A new experiment: St. Pete sells Science Center – St Pete Catalyst

A new experiment: St. Pete sells Science Center – St Pete Catalyst

December 6, 2025
Lifestyle guide: Local markets and seasonal pop-ups travelers shouldn’t miss in Chicago – AZ Big Media

Explore Chicago’s Must-Visit Local Markets and Seasonal Pop-Ups for Every Traveler

December 6, 2025
Amundi Acquires 235,432 Shares of Cognizant Technology Solutions Corporation $CTSH – MarketBeat

Amundi Acquires 235,432 Shares of Cognizant Technology Solutions Corporation $CTSH – MarketBeat

December 6, 2025

Categories

Archives

December 2025
M T W T F S S
1234567
891011121314
15161718192021
22232425262728
293031  
« Nov    
Earth-News.info

The Earth News is an independent English-language daily published Website from all around the World News

Browse by Category

  • Business (20,132)
  • Ecology (956)
  • Economy (976)
  • Entertainment (21,851)
  • General (18,596)
  • Health (10,015)
  • Lifestyle (986)
  • News (22,149)
  • People (980)
  • Politics (988)
  • Science (16,189)
  • Sports (21,475)
  • Technology (15,956)
  • World (963)

Recent News

Argentina drawn in 2026 World Cup Group J: What to know about Algeria, Austria, Jordan – The Athletic – The New York Times

Argentina drawn in 2026 World Cup Group J: What to know about Algeria, Austria, Jordan – The Athletic – The New York Times

December 7, 2025
CEO of U.S. Bancorp weighs in on the economy, tariffs and AI – MPR News

U.S. Bancorp CEO Reveals Surprising Insights on the Economy, Tariffs, and the Future of AI

December 7, 2025
  • About
  • Advertise
  • Privacy & Policy
  • Contact

© 2023 earth-news.info

No Result
View All Result

© 2023 earth-news.info

No Result
View All Result

© 2023 earth-news.info

Go to mobile version