• Our new ticketing site is now live! Using either this or the original site (both powered by TrainSplit) helps support the running of the forum with every ticket purchase! Find out more and ask any questions/give us feedback in this thread!

Google Chrome zero-day query

Status
Not open for further replies.
Sponsor Post - registered members do not see these adverts; click here to register, or click here to log in
R

RailUK Forums

Mcr Warrior

Veteran Member
Joined
8 Jan 2009
Messages
17,194
Just heard of this from a neighbour. What exactly is/was the problem?
Susceptibility to hacking when using the Chrome browser. Google obviously know about the issue(s) but apparently aren't saying all that much about it/them. Would expect there will need to be a security fix/patch released very soon, if indeed this has not already happened.
 

johntea

Established Member
Joined
29 Dec 2010
Messages
3,031
Just click the 3 'dots' in the top right corner of Chrome and click Help > About Google Chrome, will automatically update your Chrome browser to the latest one without the vunerability :)

(You just then have to close all Chrome windows and reopen for it to apply)

Might have already done it in the background
 

Tramfan

Member
Joined
19 Mar 2011
Messages
678
Location
.
Yeah, I got an email about this yesterday, and when I checked Chrome it had already updated.
 

87 027

Member
Joined
1 Sep 2010
Messages
735
Location
London
A reasonably non-technical explanation is available here. As other posters have said, if you have updated to the latest version it should be fixed


A use-after-free bug happens when one part of a program requests a block of memory to be reserved for its own exclusive access, uses that memory for a while, then relinquishes its claim on that memory block…

…only to carry on accessing that memory anyway, even after it’s been reallocated to some other part of the program, or perhaps even to another program entirely.

Imagine that you’re in the middle of a PowerPoint presentation that you’ve checked carefully and rehearsed plentifully, but just before you click through from slide 4 to slide 5, someone who thinks they’re updating slide 5 of their presentation manages to write their new data into your presentation instead. You’d end up blithely presenting someone else’s content as your own, with no inkling of the impending disaster. Even if that sort of thing happened entirely by accident, due to a genuine mistake by a trustworthy colleague, the outcome would probably be annoying, and might even be embarrassing. But if the other person knew perfectly well what they were doing, and how to orchestrate it, and if they timed their “intervention” deliberately and maliciously, the outcome could be disastrous, and perhaps even career limiting. That’s an analogy of the content crisis that use-after-free bugs can cause, often with malware implantation being the unexpected and unwanted side-effect of an exploitable use-after-free hole.
 
Status
Not open for further replies.

Top