
The Indian Computer Emergency Response Team (CERT-In) has issued a high-risk security advisory warning millions of desktop Google Chrome users about multiple critical vulnerabilities that could allow hackers to remotely compromise targeted devices. According to the vulnerability note released by the cybersecurity agency, these security flaws may create a direct risk of unauthorised remote code execution, system takeover, and denial-of-service (DoS) conditions. The warning applies to Chrome users on Windows, macOS and Linux systems, making immediate browser updates essential for affected users. CERT-In has urged users to update their browsers to protect against potential exploitation, with the agency emphasizing the critical nature of these vulnerabilities that could enable remote attackers to gain unauthorised access to sensitive information.
The CERT-In advisory covers multiple security vulnerabilities in desktop versions of Google Chrome that could allow attackers to execute arbitrary code remotely, gain unauthorised access or trigger a denial-of-service (DoS) condition. The vulnerabilities are linked to use-after-free issues in Chrome components including V8, TabStrip, HTML, Extensions and Blink. According to CERT-In, a remote attacker could exploit these flaws by tricking a user into opening a specially crafted web request. Successful exploitation could allow the attacker to execute arbitrary code or cause a DoS condition on the targeted system. As per The Times of India, attackers can exploit these weaknesses by tricking individuals into visiting crafted web pages, potentially leading to unauthorized data access or system takeovers.
The warning applies to Chrome users across Windows, macOS and Linux systems. The affected versions include Chrome builds prior to 151.0.7922.137/.138 on Windows and macOS, while Linux users running versions prior to 151.0.7922.137 are also affected. An attacker could potentially exploit the vulnerabilities by persuading a user to click a malicious link or visit a specially crafted webpage. If successful, such an attack could allow arbitrary code execution on the affected computer and potentially compromise information stored on the system. The vulnerabilities represent a high-risk scenario that could enable sophisticated attackers to gain complete control over compromised devices.
The risks include unauthorised access to sensitive information, with attackers potentially gaining access to data such as passwords and banking details. Exploitation could also corrupt system memory or disrupt critical services. The warning applies to both individual users and organisations running Chrome on affected systems. CERT-In has advised users to take immediate steps to mitigate the risks rather than continue using vulnerable versions of the browser. Google has released security updates to address the vulnerabilities, with users advised to check their Chrome browser is running the latest available version and install any pending updates.
To manually check for an update, users can open Google Chrome on a computer and click the three-dot menu in the top-right corner. They then need to hover over Help in the drop-down menu and select About Google Chrome. Chrome will automatically check for the latest version and download an available update. Once the update has been downloaded, users need to click Relaunch to complete the installation and activate the security patches. The warning highlights the importance of keeping desktop browsers updated, particularly when security fixes address vulnerabilities that could potentially be exploited through malicious webpages or links. Google has rolled out patches to address the issue, prompting cybersecurity authorities to urge users to manually check for updates via the browser menu, install the latest version, and relaunch Chrome to secure their devices against potential attacks.