Skip to main content

Security Alert: Urgent Google Chrome/Microsoft Edge patch

Date:
2022-09-06 13:34:00
Status:
Closed
Brief Description:
A zero-day vulnerability in Google Chrome and Microsoft Edge for Windows, macOS, and Linux. "Insufficient data validation" in Mojo the codebase that Google Chrome’s built on. Google states this vulnerability is being actively exploited. Patch now.
Current Status:
N/A
Services Affected:
Certified Desktop
Full Description:
A zero-day vulnerability in Google Chrome and Microsoft Edge for Windows, macOS, and Linux. "Insufficient data validation" in Mojo, a collection of runtime libraries used by Chromium, the codebase that Google Chrome’s built on. Google states this vulnerability is being actively exploited. Patch now.

For Google Chrome:
To check if your browser is updated, navigate to Settings > Help > About Google Chrome or chrome://settings/help in the address bar. If your Chrome browser is listed as 105.0.5195.102 or higher, you are protected.

Users should apply the following updates:
• Chrome 105.0.5195.102 or higher

For Microsoft Edge:
To check if your browser is updated, navigate to Menu > Help and Feedback > About Microsoft Edge, or edge://settings/help in the address bar. If your Edge browser is listed as 105.0.1343.27 or higher, you are protected.

Users should apply the following updates:
• Edge 105.0.1343.27 or higher

Certified Desktop customers:
• Windows: Patches for Google Chrome and Microsoft Edge will be available this afternoon with an install deadline of 4:00pm on Wednesday, September 7.

• macOS: A patch for Google Chrome will be available this afternoon with an install deadline of 4:00pm on Wednesday, September 7. Users of Microsoft Edge should manually check for updates and install them.

Users who do not have a managed computer should check for updates and install them.

For more information refer to the references below.
Bleeping Computer: https://www.bleepingcomputer.com/news/security/google-chrome-emergency-update-fixes-new-zero-day-used-in-attacks/
Google Chrome Releases: https://chromereleases.googleblog.com/2022/09/stable-channel-update-for-desktop.html
Microsoft Edge Security Release Notes: https://docs.microsoft.com/en-us/deployedge/microsoft-edge-relnotes-security
CIT TDX ID: