City
Epaper

CERT-In warns users of multiple bugs in Google Chrome, Zoho software

By IANS | Updated: July 7, 2022 15:05 IST

New Delhi, July 7 The Indian Computer Emergency Response Team (CERT-In), which comes under the IT Ministry, has ...

Open in App

New Delhi, July 7 The Indian Computer Emergency Response Team (CERT-In), which comes under the IT Ministry, has warned users of multiple vulnerabilities in Google Chrome which could allow a remote attacker to execute arbitrary code and denial-of-service (DoS) conditions on the targeted system.

A remote attacker could exploit these vulnerabilities by sending specially crafted requests on the targeted system.

"Successful exploitation of these vulnerabilities could allow an attacker to execute arbitrary code and denial-of-service (DoS) conditions on the targeted system," said CERT-In the advisory late on Wednesday.

These vulnerabilities exist in Google Chrome due to 'Heap Buffer' overflow in 'WebRTC', 'Type Confusion in V8' and 'Use after Free' in Chrome OS Shell.

The vulnerability (CVE-2022-2294) is being exploited in the wild, said the cyber agency, adding that the users are advised to apply patches urgently.

CERT-In also advised users against a 'Remote Code Execution' vulnerability that has been reported in a Zoho Corporation software which could be exploited by an unauthenticated remote attacker to execute arbitrary code on the targeted system.

This vulnerability exists in 'Zoho ManageEngine ADAudit Plus' due to a 'misconfigured XML' parser that processes user-supplied input without sufficient validation.

"Successful exploitation of this vulnerability could allow an unauthenticated remote attacker to execute arbitrary code on the targeted system," warned the cyber agency, advising the users to upgrade to the latest Zoho 'ManageEngine ADAudit Plus' security build update.

Disclaimer: This post has been auto-published from an agency feed without any modifications to the text and has not been reviewed by an editor

Tags: Secure ShellgoogleWord on macWho dgMicrosoft incUs google & youtubeSk duaDan patelBacPrivate institutesStory of reality tv
Open in App

Related Stories

TechnologyIPL 2026 Google Doodle: Search Engine Giant Rolls Out Neon-Themed Doodle to Celebrate Start of Indian Premier League

TechnologyWhy YouTube Witness Global Outage? TeamYouTube Reveals Reason

TechnologyYouTube Down: TeamYouTube Says Its Teams Are Looking Into Global Outage

TechnologyRamadan 2026 Moon Sighting Google Doodle: Search Engine Rolls Out ‘Search Crescent Moon’ Game to Wish Ramadan Kareem

TechnologyTech Giants Plan $650 Billion AI Investment in 2026 to Dominate Global Market

International Realted Stories

InternationalEnsuring safety of Indian nationals in Gulf top priority: MEA's Aseem R Mahajan amid West Asia conflict

InternationalEast Turkistan Government in Exile terms Baren Uprising a 'legitimate anti-colonial resistance' and marks 36th anniversary

InternationalPakistan’s 5G launch faces steep infrastructural, financial hurdles

InternationalIMF tells Pakistan to remove subsidy on fuels

InternationalAbrupt petrol price cut after hike in Pak reflects a deeper policy failure: Report