Moneycontrol PRO
Black Friday Sale
Black Friday Sale
HomeTechnologyGovernment issues warning for Mac and Windows Chrome browsers and Chromebooks, here's what you need to do

Government issues warning for Mac and Windows Chrome browsers and Chromebooks, here's what you need to do

CERT-In alerts users about critical vulnerabilities in Google Chrome and ChromeOS, urging immediate updates to prevent data breaches and system compromises.

January 27, 2025 / 08:33 IST
Chrome

India’s cybersecurity watchdog, CERT-In, has issued a critical warning for users of Google Chrome on Mac, Windows, and Chromebooks. The alert highlights multiple vulnerabilities in the browser and ChromeOS that could allow hackers to compromise sensitive data, execute arbitrary code, or cause system instability. Users are urged to immediately update their browsers and operating systems to mitigate these risks.

Chrome warning for Mac

CERT-In has identified two major vulnerabilities—CIVN-2025-0007 and CIVN-2025-0008—affecting Google Chrome on Mac. These flaws, rated as critical and highly severe, impact Chrome versions before 132.0.6834.83/8r. Exploiting these vulnerabilities, attackers could execute arbitrary code, cause denial of service (DoS), or bypass security restrictions. The issues stem from out-of-bounds memory access, improper implementation in navigation, and insufficient data validation in extensions.

Chrome warning for Windows

Windows users are equally at risk, with the same vulnerabilities affecting Chrome versions before 132.0.6834.110/111. Hackers can exploit these flaws by sending specially crafted requests, potentially leading to data exfiltration, system crashes, or unauthorised access to sensitive information. CERT-In emphasises that these vulnerabilities pose a significant threat to both individual users and organisations.

ChromeOS warning

ChromeOS, the operating system powering Chromebooks, is also under threat. Versions prior to 16093.68.0 (browser version 132.0.6834.94) are vulnerable to spoofing, cross-site scripting, and remote code execution. These flaws arise from stack buffer overflow, integer overflow, and out-of-bounds memory access. A remote attacker could exploit these weaknesses by executing a malicious webpage, potentially gaining access to sensitive data or bypassing security controls.

Affected devices

The vulnerabilities primarily impact desktops, laptops, and Chromebooks running outdated versions of Chrome or ChromeOS. Smartphone users are less affected, but CERT-In advises all users to stay vigilant.

Why you shouldn’t ignore this

Ignoring these warnings could lead to severe consequences, including data breaches, system instability, and unauthorised access to sensitive information. Hackers are actively exploiting such vulnerabilities, making timely updates crucial.

What you can do

To protect your devices, update Google Chrome and ChromeOS to the latest versions immediately. Visit the official Chrome Releases blog for detailed instructions. Regularly check for updates and enable automatic updates to ensure your system remains secure.

Invite your friends and family to sign up for MC Tech 3, our daily newsletter that breaks down the biggest tech and startup stories of the day

Moneycontrol News
first published: Jan 27, 2025 08:32 am

Discover the latest Business News, Sensex, and Nifty updates. Obtain Personal Finance insights, tax queries, and expert opinions on Moneycontrol or download the Moneycontrol App to stay updated!

Subscribe to Tech Newsletters

  • On Saturdays

    Find the best of Al News in one place, specially curated for you every weekend.

  • Daily-Weekdays

    Stay on top of the latest tech trends and biggest startup news.

Advisory Alert: It has come to our attention that certain individuals are representing themselves as affiliates of Moneycontrol and soliciting funds on the false promise of assured returns on their investments. We wish to reiterate that Moneycontrol does not solicit funds from investors and neither does it promise any assured returns. In case you are approached by anyone making such claims, please write to us at grievanceofficer@nw18.com or call on 02268882347