Rewterz
Rewterz Threat Alert – Emotet is Back from Holiday
January 20, 2020
Rewterz
Rewterz Threat Alert – STOP (djvu) Ransomware Actively Spread
January 20, 2020

Rewterz Threat Advisory – Multiple Vulnerabilities in Google Chrome Could Allow for Arbitrary Code Execution

Severity

High

Analysis Summary

Multiple vulnerabilities have been discovered in Google Chrome, the most severe of which could result in arbitrary code execution.

Use-after-free in speech recognizer (CVE-2020-6378, CVE-2020-6379)
Extension message verification error (CVE-2020-6380)
Protections to mitigate Windows ECC certificate validation vulnerability CVE-2020-0601 (CVE-2020-0601)

Impact

Arbitrary Code Execution

Affected Vendors

Google

Affected Products

  • Google Chrome Canary
  • Google Chrome versions prior to 79.0.3945.130

Remediation

Update to latest version of Google chrome.