14 New 0-Day Vulnerabilities in Chrome OS – Update Your Chrome OS ASAP

There is an advisory from Google for those who have been using Chrome OS. In the advisory, Google mentioned 14 new 0-day vulnerabilities in Chrome OS and asked users to upgrade the operating system as soon as possible.

Google has fixed these vulnerabilities by rolling out an update on the 31st of August. Well, the company hasn’t notified any traces of active exploitation in the wild. The advisory has a list of 14 vulnerabilities, of which 4 are identified as high, and the remaining 10 are medium in severity. The reported vulnerabilities would be abused to carry out arbitrary code execution and denial of service attacks on the vulnerable version of Chrome OS by remote attackers.

List 14 New 0-Day Vulnerabilities in Chrome OS

In the update Google shared, it has fixed these 14 0-day vulnerabilities in Chrome OS, of which 4 is High, and the remaining 10 are Medium in severity. Please see the list as under. Successful exploitation could lead to arbitrary code execution and denial of service attacks on the vulnerable version of ChromeOS by remote attackers.

  1. CVE-2022-2857: It is a High severity vulnerability in Blink
  2. CVE-2022-2998: It is a High severity vulnerability in Browser Creation
  3. CVE-2022-2607: It is a High severity vulnerability in WebUI
  4. CVE-2022-2606: It is a High severity vulnerability in Managed devices API
  5. CVE-2022-2859: It is a Medium severity vulnerability in Chrome OS Shell
  6. CVE-2022-2860: It is a Medium severity vulnerability due to insufficient policy enforcement in Cookies.
  7. CVE-2022-2861: It is a Medium severity vulnerability due to inappropriate implementation in Extensions API
  8. CVE-2022-2624: It is a Medium severity Heap buffer overflow vulnerability in PDF
  9. CVE-2022-2614: It is a Medium severity vulnerability in Sign-In Flow
  10. CVE-2022-2621: It is a Medium severity vulnerability in Extensions
  11. CVE-2022-2612: It is a Medium severity Side-channel information leakage vulnerability in Keyboard input
  12. CVE-2022-2620: It is a Medium severity vulnerability in WebUI
  13. CVE-2022-2615: It is a Medium  severity vulnerability due to insufficient policy enforcement in Cookies
  14. CVE-2022-2617: It is a Medium severity vulnerability in Extensions API

Chrome OS Versions Affected by These 0-Day Vulnerabilities

It’s been said that all the LTS versions prior to 96.0..4664.219 (Platform Version: 14268.104.0).

How to Fix These 0-Day Vulnerabilities in Chrome OS?

Google responded and released updates on 31st August to fix all the 14 New 0-Day Vulnerabilities in Chrome OS. All the Chrome OS users are suggested to upgrade to v96.0..4664.219 (Platform Version: 14268.104.0). Please refer to the security advisory by Google.

How to Upgrade Chrome OS?

Well, Chrome OS is designed to fetch upgrades by itself. Most of the time, auto-upgrade will work. Your Chrome OS didn’t receive upgrades for any reason, and you will have to kick start the process manually.  Then you can follow any one of the methods shown here.

Method 1: Manual Upgrade From Settings

  1. Click on the Settings icon on the Task Bar.
  2. Choose the ‘About Chrome OS‘.
  3. Click on ‘Check for Updates‘. The upgrade process will get started if your OS is connected to the internet.

For some reason, if auto-upgrade didn’t get fired up. Follow the Method 2.

Method 2: Upgrade Using Brunch Framework

Time needed: 20 minutes.

Method 2: Upgrade using the brunch framework

  1. Open Terminal

    Click Crtl + Alt + T and keys together to open Crosh Shell.

    Open Terminal in Chrome OS

  2. Open shell

    Enter ‘shell‘ command to open the shell.

    Open shell in Chrome OS

  3. Download brcr-update

    Use this curl command to download brcr-update as shone here:

    $ curl -L -o – https://git.io/JLh1V | sudo bash

    Download brcr-update on Chrome OS

  4. Update brcr-update

    Run this command. That’s it.

    $ brcr-update

Method 3: Manually Update Brunch and Chrome OS Together

  1. Download the latest Brunch release and the latest recovery matching your install and extract the bin.
  2. Click Crtl + Alt + T and keys together to open Crosh Shell.
  3. Update the Brunch using the following command:
$ sudo chromeos-update -r ~/Downloads/<path to recovery filw> -f ~/Downloads/<path of brunch archive file>
14 New 0-Day Vulnerabilities in Chrome OS – Update Your Chrome OS ASAP

4. Restart the Chrome OS.

Method 4: Upgrade Only Chrome Os Skipping Brunch Framework

This is the easiest way to upgrade the Chrome OS. All you need to do enable_updates framework option, then carry out the upgradation from the ‘Settings’ as shown in Method 1. This is not the recommended method.

  1. Click Crtl + Alt + T and keys together to open Crosh Shell.
  2. Open the Brunch Configuration Menu using the below command:
$ sudo edit-brunch-config

3. Add enable_updates as shone in the picture. Save the changes.

14 New 0-Day Vulnerabilities in Chrome OS – Update Your Chrome OS ASAP
  1. Reboot the Chrome OS.
  2. Click on the Settings icon on the TaskBar.
  3. Choose the ‘About Chrome OS‘.
  4. Click on ‘Check for Updates‘. The upgrade process will get started if your OS is connected to the internet.

Watch this video created by The Artmann.

Source: The Artmann

We hope this post will help you know how to patch the 14 new 0-day vulnerabilities in Chrome OS. Please share this post if you find this interested. Visit our social media page on FacebookLinkedInTwitterTelegramTumblr, & Medium and subscribe to receive updates like this.

原创文章,作者:ItWorker,如若转载,请注明出处:https://blog.ytso.com/287527.html

(0)
上一篇 2022年9月20日
下一篇 2022年9月20日

相关推荐

发表回复

登录后才能评论