Skip to main content

Google fixes Flash security bug before Adobe

Flash LogoGoogle today preempted Adobe by fixing a “critical” security issue with Adobe’s Flash Player. Google’s fix, however, only covers its Chrome Web browser. Users of other browsers will likely have to wait for Adobe to release an official patch, which is planned for release sometime this week.

The “zero-day” bug was first brought to attention of the public last week after infected .swf files (Flash’s extension) — which were embedded in Excel documents (.xls) — began appearing in email inboxes. Opening the compromised file could cause a system to crash or, at the very worst, could result in a hacker “[taking] control of the affected system.”

Microsoft has said that user’s of Office 2010 are not vulnerable through a security system included in the software suite. Users of older versions of Windows who are running Chrome will only be safe if they do not have Flash for Internet Explorer installed and only stick to using Flash through Chrome. Mac users may be safe for the moment, but it’s suspected that vulnerability could be adjusted to exploit Apple products. If you’re a non-Chrome user, you’re best bet would be to remove Flash until Adobe releases the patch. If you are a Chrome user, be sure to update.

Google’s owes its speediness in releasing the Chrome fix in part to its close relationship with Adobe. Through an agreement, Google is granted access to early builds of Flash before they’re released to the public. That gives the company a head-start on testing — something it takes very seriously when it comes to the security of its Chrome browser.

While Google only had to worry about testing the fix for Chrome, Adobe will have to test its patch on around 60 system configurations before its ready for release.

Topics
Aemon Malone
Former Digital Trends Contributor
Google just thwarted the largest HTTPS DDoS attack in history
A depiction of a hacker breaking into a system via the use of code.

Google has confirmed that one of its cloud customers was targeted with the largest HTTPS distributed denial-of-service (DDoS) attack ever reported.

As reported by Bleeping Computer, a Cloud Armor client was on the receiving end of an attack that totaled 46 million requests per second (RPS) at its peak.

Read more
Zoom just fixed a major security flaw on Mac. Here’s why you should update now
The Logitech Brio 4K Pro attached to a Macbook.

If you have Zoom installed on your MacBook, you'll want to update the app right now. Zoom spent the weekend patching a major security flaw in its Mac app, and the update is available right now.

According to The Verge, it all began at Def Con, a computer security and hacker conference in Las Vegas. The founder of the security non-profit Objective-See and an ex-NSA security analyst, Patrick Wardle, took to the stage on Friday and presented a stunning find: a massive security vulnerability in the Zoom installer for MacBooks.

Read more
A massive Google Search bug is affecting major publishers
A laptop rests on a bench outside with google search open on-screen.

Google has reported an issue with its search engine that is currently affecting publishers.

Recent articles and content from several sources appear to have a number of challenges, including newly published articles not showing up in Google search at all, as has been noted by CNET.

Read more