City
Epaper

CERT-In finds vulnerabilities in Apple iTunes, Google Chrome

By IANS | Updated: May 11, 2024 15:25 IST

New Delhi, May 11 The Indian Computer Emergency Response Team (CERT-In), which comes under the Ministry of Electronics ...

Open in App

New Delhi, May 11 The Indian Computer Emergency Response Team (CERT-In), which comes under the Ministry of Electronics & Information Technology, has warned users of vulnerabilities in Apple iTunes and Google Chrome for desktop which could allow an attacker to execute arbitrary code on the targeted system.

The affected software includes Apple iTunes versions prior to 12.13.2 for Windows.

For Chrome for Desktop, the affected software includes -- versions prior to 124.0.6367.201/.202 (for Windows and Mac) and versions before 124.0.6367.201 (for Linux).

"A vulnerability has been reported in Apple iTunes which could be exploited by a remote attacker to execute arbitrary code on the targeted system," said the CERT-In advisory.

The 'Remote Code Execution' vulnerability exists in the Apple Product due to improper checks in the CoreMedia component. A remote attacker could exploit this vulnerability by sending a specially crafted request, the advisory mentioned.

In addition, the cyber agency said that the reported vulnerabilities exist in Google Chrome due to use-after-free errors in Visuals & ANGLE components; and heap buffer overflow in WebAudio.

"A remote attacker could exploit these vulnerabilities by executing a specially crafted HTML page to trigger heap corruption," CERT-In noted.

"Successful exploitation of these vulnerabilities could allow the remote attacker to compromise the targeted system," it added.

The agency also suggested users to apply appropriate security updates as mentioned by the companies.

Disclaimer: This post has been auto-published from an agency feed without any modifications to the text and has not been reviewed by an editor

Open in App

Related Stories

NationalYellow alert in 9 Kerala districts as heavy rain causes widespread disruption

EntertainmentRyan Gosling unveils his 'Project Hail Mary' 'space caveman' character at Comic-Con

EntertainmentSanjeev Kapoor remembers late father, thanks mother in heartfelt Parent’s Day tribute

NationalPunjab Police bust Pak-backed arms, drug smuggling network; 5 arrested

Other SportsArsenal signs striker Viktor Gyokeres on 5-year deal

Business Realted Stories

BusinessIndia's forex reserves drop by $1.18 bn to $695.49 bn, third consecutive weekly decline

BusinessTrade deal uncertainty weighing on private sector investment: UBS

BusinessInfrastructure InvITs to surpass Rs 8 lakh crore AUM by FY27: Crisil Ratings

BusinessZen Technologies' profit plunges 53 pc sequentially to Rs 53 crore in Q1

BusinessAdani Defence's Kanpur facility strengthening India's quest for self-reliance, makes use of AI, data analytics