Indian cyber agency finds multiple bugs in Google Chrome,SAP Products

The vulnerabilities in Google Chrome for desktop affect versions prior to 126.0.6478.54 for Linux and versions before 126.0.6478.56/57 for Windows and Mac. For SAP products, the affected software includes SAP Financial Consolidation, NetWeaver AS Java (Meta Model Repository), NetWeaver AS Java (Guided Procedures), NetWeaver and ABAP platform, Document Builder (HTTP service), Bank Account Management, among others.

CERT-In’s advisory states, “Multiple vulnerabilities have been reported in Google Chrome that could allow a remote attacker to execute arbitrary code on the targeted system.” These issues in Google Chrome are due to Type Confusion in V8; Use after free in Dawn, V8, BrowserUI, Audio; Inappropriate implementation in Dawn, DevTools, Memory Allocator, Downloads; Heap buffer overflow in Tab Groups, Tab Strip; and Policy Bypass in CORS. Attackers could exploit these by convincing victims to visit specially crafted web pages.

In SAP products, the vulnerabilities could enable attackers to perform cross-site scripting (XSS), bypass authorization checks, upload unauthorized files, access sensitive information, or cause denial of service conditions.

CERT-In recommends users apply the necessary security updates provided by the companies to protect against these vulnerabilities and avoid phishing attacks.

- Advertisement -

LEAVE A REPLY

Please enter your comment!
Please enter your name here

Latest Articles

error: Content is protected !!

Sign Up for CXO Digital Pulse Newsletters

Sign Up for CXO Digital Pulse Newsletters to Download the Research Report

Sign Up for CXO Digital Pulse Newsletters to Download the Coffee Table Book

Sign Up for CXO Digital Pulse Newsletters to Download the Vision 2023 Research Report

Download 8 Key Insights for Manufacturing for 2023 Report

Sign Up for CISO Handbook 2023

Download India’s Cybersecurity Outlook 2023 Report

Unlock Exclusive Insights: Access the article

Download CIO VISION 2024 Report

Share your details to download the report

Share your details to download the CISO Handbook 2024