• Home
  • Startup
  • Money & Finance
  • Starting a Business
    • Branding
    • Business Ideas
    • Business Models
    • Business Plans
    • Fundraising
  • Growing a Business
  • More
    • Innovation
    • Leadership
Facebook Twitter Instagram
  • Newsletter
  • Submit Articles
  • Privacy
  • Advertise
  • Contact
Facebook Twitter Instagram
FundsEdu.Com
  • Home
  • Startup
  • Money & Finance
  • Starting a Business
    • Branding
    • Business Ideas
    • Business Models
    • Business Plans
    • Fundraising
  • Growing a Business
  • More
    • Innovation
    • Leadership
Subscribe for Alerts
FundsEdu.Com
Innovation

New Critical Google Chrome Payments Security Issue Confirmed

adminBy adminJune 14, 2023No Comments3 Mins Read

Hot on the heels of the recent emergency Google Chrome security update addressing a zero-day exploit, already seen in the wild, comes another critical Chrome browser security update. This one lists four vulnerabilities as being included, one of which is a critical issue in the browser ‘autofill payments’ function which automatically enters payment details in online forms.

What is CVE-2023-3214?

Although CVE-2023-3214 doesn’t have quite the same feeling of urgency as CVE-2023-3079, as there are no known exploits in the wild at this point, that doesn’t mean it’s not to be taken just as seriously. The fact is that this new security issue is rated as critical and impacts the autofill payments function of the Google Chrome browser. Whenever you hear ‘critical’ and ‘payments’ uttered in the same breath, you know it’s serious.

What we don’t know right now is precisely what the vulnerability entails. This is not unusual as Google always withholds such technical information until such a time as the majority of users will have received the automated update rollout, and so have been given the chance to activate it.

What we do know is that it is a ‘use-after-free’ vulnerability. The Mitre definition of a use-after-free vulnerability is where memory is referenced after it has been freed, which causes the program to either crash, use unexpected values or execute code. You can read the full technical explanation here.

Four new security vulnerabilities are fixed in this Chrome update

CVE-2023-3214 isn’t the only vulnerability to be addressed in this Google Chrome security update, although it is the only one which earns a critical rating. There are three other vulnerabilities that are patched, all of them carrying a high criticality rating.

These are:

  • CVE-2023-3215, which is a use after free vulnerability in the Chromium WebRTC, a real time communications system for audio, video and data.
  • CVE-2023-3216 which is a type confusion vulnerability in the V8 JavaScript engine.
  • CVE-2023-3217 which is another use after free vulnerability, this time in the Chrome browser WebXR, an augmented reality and virtual reality application programming interface.

How to make sure your browser is protected

Head for the Help|About option in your Google Chrome menu, and if the update is available, it will automatically start downloading. It may take a few days for the update to reach everyone, so be patient if you are not seeing it yet. Also, remember what I wrote earlier, and restart your browser after the update has been installed, or it will not activate, and you will still be vulnerable to attack. The June 13 confirmation from Google gives the updated browser version numbers as 114.0.5735.133 for Mac and Linux and 114.0.5735.133/134 for Windows.

Other browsers that use the Chromium engine will also be getting updates. These may already have landed or will be forthcoming in the next few days. Check your Brave, Edge, Opera or Vivaldi browsers to ensure the update is installed and activated.

Read the full article here

Related Articles

ASUS Zenbook S 16 Review — Ryzen AI 9 HX 370 Processor At Its Best

Innovation December 17, 2024

FBI Hacking Warning—More Bad News For iPhone, Android Users

Innovation December 16, 2024

We’ll Need To Anticipate AI Using A Lot Of Resources In Tomorrow’s World

Innovation December 15, 2024

NYT ‘Connections’ Hints And Answers For Sunday, December 15

Innovation December 14, 2024

A 2024 Gift Guide For The Dungeons And Dragons Dungeon Masters

Innovation December 13, 2024

Meet 5 ‘Otherworldly’ Ancient Animals—Preserved In Stunning Detail At This Iconic Fossil Hunting Site

Innovation December 12, 2024
Add A Comment

Leave A Reply Cancel Reply

Sections
  • Growing a Business
  • Innovation
  • Leadership
  • Money & Finance
  • Starting a Business
Trending Topics
  • Branding
  • Business Ideas
  • Business Models
  • Business Plans
  • Fundraising
© 2025 Startup Dreamers. All Rights Reserved.
  • Privacy Policy
  • Terms of use
  • Press Release
  • Advertise
  • Contact

Type above and press Enter to search. Press Esc to cancel.