CERT-In Warns of Critical Security Flaws in macOS and Chrome

CERT-In Issues High-Severity Alert for macOS and Chrome Users

India’s Computer Emergency Response Team (CERT-In) has issued a critical security warning for millions of users of Apple macOS and Google Chrome. The agency warns of multiple high-risk vulnerabilities that could let attackers take complete control of affected systems.

Key Takeaways

  • High-Severity Alert: CERT-In warns of critical flaws in macOS and Chrome.
  • Risk: Attackers can execute arbitrary code, steal data, or crash systems.
  • Affected Versions: Outdated macOS (Sonoma, Ventura, Monterey) and Chrome versions.
  • Immediate Action: Users must update their software immediately.

Details of the macOS Vulnerabilities

The vulnerability note, CIVN-2024-0170, details risks for specific macOS versions:

  • macOS Sonoma versions before 14.4
  • macOS Ventura versions before 13.6.5
  • macOS Monterey versions before 12.7.4

The flaws exist in core components like App Intents, AppleAVD, Audio, Bluetooth, and CloudKit. A remote attacker could send specially crafted requests to exploit these weaknesses, potentially bypassing security, executing malicious code, disclosing sensitive information, or causing a denial-of-service attack.

Google Chrome Security Flaw

For Google Chrome, the warning highlights “use after free” vulnerabilities in the FedCM (Federated Credential Management) component. The affected versions are prior to 123.0.6312.58/.59 for Windows and Mac, and prior to 123.0.6312.58 for Linux.

“A remote attacker could exploit these vulnerabilities by sending a specially crafted request to the targeted system,” CERT-In stated.

Successful exploitation could allow an attacker to run arbitrary code on a victim’s machine.

How to Protect Your System

CERT-In’s primary advice is to apply security updates immediately:

  • macOS Users: Update to macOS Sonoma 14.4, Ventura 13.6.5, Monterey 12.7.4, or later.
  • Chrome Users: Update to version 123.0.6312.58/.59 (Windows/Mac) or 123.0.6312.58 (Linux) or later.

For broader online safety, the agency recommends:

  • Exercise extreme caution with links in emails or messages from unknown sources.
  • Avoid visiting untrusted websites.
  • Download software only from official app stores or trusted sources.
  • Enable automatic updates for your OS and applications.

Latest

Apple WWDC 2026 dates announced: iOS 27, new Siri, and more to expect at Apple’s next big event

Tech News News: Apple has confirmed that its annual Worldwide Developers Conference will run from June 8-12, with a keynote kicking things off at Apple Park on

US senator Elizabeth Warren in a letter to Defense Secretary Pete Hegseth on Anthropic’s ‘supply chain risk’ tag: ‘I am particularly concerned…’

Tech News News: Senator Elizabeth Warren has questioned the the Pentagon’s blacklisting of AI company Anthropic. Warren has reportedly sent formal letter to D

Reddit CEO Steve Huffman on why he wants to hire more Gen Z college graduates: ‘They’re really good at…’

Tech News News: Reddit CEO Steve Huffman says the company plans to increase hiring of recent college graduates. The chief executive of the social media platform

‘AI will be sold like electricity and water by OpenAI’: Sam Altman explains how you’ll pay by usage, not subscription

Tech News News: The field of artificial intelligence is evolving towards a system in which it is considered a basic service rather than a product. At the BlackR

Want a Wordle win? Try this surprising tip straight from the game’s creator Josh Wardle

Gaming News: Wordle was created by Josh Wardle as a daily word puzzle designed for his partner during the COVID-19 lockdowns. The game quickly gained popularity

Topics

Why the US and Iran may exit a costly war

A popular narrative doing the rounds is that the US and Israel underestimated Iran and that the latter is giving them hell by fighting back heroically

Need a stronger WTO to fight Trump’s trade pivot

The Cameroon ministerial meeting this week offers a platform for countries, including India, to secure the global trade body from American unilateralism

Jal Jeevan Mission 2.0: Beyond pipes & pumps

India has already demonstrated that universal rural water access is achievable with determination and collaboration

Bhutan delegation visits UPSC to study examination management system

New Delhi, A three-member delegation from the Royal Civil...

Rajasthan’s hidden secret to fight summers, and why it matters now

Known as Orans, these community-protected landscapes bring together vegetation, water, and local belief to create pockets where heat is less intense and life co

The Strait of Hormuz and India’s Structural Energy Vulnerability

As per IEA'S Oil Market Report, global oil supply is already estimated to have fallen by at least 8 million barrels per day in March alone

Why Trump is desperate to end the war and Iran is in no hurry

Donald Trump is keen to cut losses and end the Iran war before it becomes even a bigger liability for him and the United States. However, Iran is reluctant to p
spot_img

Related Articles

Popular Categories

spot_imgspot_img