Microsoft patches active zero-day Chromium flaw in Edge

representational image of a cloud firewall
(Image credit: Pixabay)

A fix for a severe vulnerability in Google’s Chromium web browser that was reportedly being exploited in the wild has now been applied to the stable branch of the Microsoft Edge browser.

The vulnerability, tracked as CVE-2021-21193, was reported by an anonymous security researcher earlier in March. Google rushed out a patch for Google Chrome soon after, and now Microsoft has rolled it into its Chromium-based Edge browser too.

“Google is aware of reports that an exploit for CVE-2021-21193 exists in the wild,” noted the search engine giant as it released an update for Google Chrome to address the vulnerability as well as a couple of others.

The vulnerability, which ranks 8.8 out of 10 in the CVSS vulnerability rating scale, making it high-severity, exists in the Blink rendering engine.

It’s described as a use-after-free vulnerability, which experts suggest exists due to the incorrect use of dynamic memory during the execution of an app, which is the Blink rendering engine in this case.

Reportedly, due to Blink’s inability to properly clear its memory, it allowed an attacker to execute arbitrary code or corrupt data. Google however didn’t share any details about how the vulnerability was being exploited, apart from stating that it was aware of the flaw being used by hackers.

Microsoft has now followed Google’s stead and has released patches for the Blink vulnerability in the stable channel of its Edge web browser, which is powered by the same Blink engine as Google’s Chrome.

Via: MSPowerUser

Mayank Sharma

With almost two decades of writing and reporting on Linux, Mayank Sharma would like everyone to think he’s TechRadar Pro’s expert on the topic. Of course, he’s just as interested in other computing topics, particularly cybersecurity, cloud, containers, and coding.

Read more
The best free firewall
Microsoft fixes Power Pages security flaw, tells users to be on their guard
Representational image depecting cybersecurity protection
Hackers are breaking SonicWall products to target business networks
Representational image of a cybercriminal
Microsoft just patched a host of worrying security issues, so update now
Outlook
Dangerous Microsoft Outlook flaw could let hackers send out malware via email
An option to add Ambient Music buttons to the iOS 18.4 Control Center.
Apple fixes dangerous zero-day used in attacks against iPhones and iPads
Flag of the People's Republic of China overlaid with a technological network of wires and circuits.
One of the biggest flaws exploited by Salt Typhoon hackers has had a patch available for years
Latest in Software & Services
woman listening to computer
AWS vs Azure: choosing the right platform to maximize your company's investment
A person at a desktop computer working on spreadsheet tables.
Trello vs Jira: which project management solution is best for you?
Autonomous finance
Quickbooks vs Quicken: what are the main strengths and weaknesses for your business
finance
Quickbooks vs Xero: which is the best for your business?
Group of people meeting
Zoom vs Google Meet: which is the best video conferencing tool for your business?
Fingers typing on a computer keyboard.
Microsoft 365 Personal vs Microsoft 365 Family: are there any real differences?
Latest in News
Metroid Prime 4
I reckon the Nintendo Switch 2 could launch with Metroid Prime 4 – here’s why
Samsung Galaxy Z Fold 6
New rumors predict a foldable iPhone will launch next year – and cost almost twice as much as the iPhone 16 Pro Max
Pebble smartwatch countdown
Pebble confirms its smartwatch announcement is just hours away
Logo of YouTube Shorts
Is YouTube auto-playing Shorts when you open the app? Well, you’re not alone - here’s how to fix it
Google DeepMind panel discussion
“More sovereignty and protection” - Google goes all-in on UK AI with data residency, upskilling projects, and startup investments
Nintendo Switch 2
Nintendo Switch 2 expected to have AI upscaling and I can't wait to finally play Tears of the Kingdom with upgraded graphics