Critical Security Vulnerability

Forumite Members General Topics Tech Security Talk Critical Security Vulnerability

Viewing 2 posts - 1 through 2 (of 2 total)
  • Author
    Posts
  • #77812
    wasbitwasbit
    Participant
      @wasbit
      Forumite Points: 245

      A bit late due to the forum being down.

      “A critical security vulnerability affects nearly every web browser, almost any program using web technologies, and really any application that can open an image in the WebP format.
      This bug in the WebP image format created by Google is already being actively exploited on the web, and a ton of applications on your PC are going to need updates to secure themselves.
      The bug affects every big web browser (including Chrome, Firefox, Edge, Brave, and the Tor Browser), any application using the Electron framework, cross-platform apps built with Google’s Flutter framework, and any program that uses the libwebp library to open WebP images.
      Any vulnerable application will need an update from its developers. The big web browser makers have already released updates, but the problem extends far beyond browsers. Be sure to install any available updates for your programs.
      This bug highlights one issue with how applications are developed for a modern PC. Your browser has its own browser rendering engine. Then, many of the applications you install have their own built-in browser engines (thanks to Electron and similar technologies.) When a bug like this one is discovered, every single program needs to update its built-in software separately.”

      https://www.theverge.com/2023/9/13/23872484/chrome-firefox-brave-edge-security-update-webp-vulnerability

      --
      Regards
      wasbit

      Rig 1: Optiplex 3050 SFF
      Rig 2: Asus ROG G20CB (rebuilt wreck)
      Rig 3: HP Elitebook 8440P

      Dear Starfleet, hate you, hate the Federation, taking Voyager. - Janeway

      #77813
      Ed PEd P
      Participant
        @edps
        Forumite Points: 39

        I guess in the short term all we can do is hope, keep our software up to date, run a virus scan more frequently, and hope!

        Good find!

      Viewing 2 posts - 1 through 2 (of 2 total)
      • You must be logged in to reply to this topic.