CERT-In Warns Chrome and Android Users About High-Risk Security Threats

The Indian Computer Emergency Response Team (CERT-In) has issued a high-risk security alert for users of Google Chrome and Android smartphones. The advisory highlights critical vulnerabilities that could allow attackers to take control of devices or steal sensitive data.
For Chrome users, the affected versions include those before 137.0.7151.55 for Linux and before 137.0.7151.55/56 for Windows and Mac. CERT-In warns that these flaws could let remote attackers run harmful code or crash systems by tricking users into visiting malicious websites. The issues stem from improper implementations in components like the Background Fetch API and FileSystemAccess API. Users are urged to update their browsers through the stable channel immediately.
On the Android front, the alert covers versions 13, 14, and 15, used across smartphones from various manufacturers. The vulnerabilities, found in system components like Android Runtime, Framework, and chipsets from Qualcomm and others, could let attackers gain unauthorized access, elevate privileges, or disrupt system operations. CERT-In recommends users install software updates as soon as they are rolled out by device manufacturers.
Source: Business Standard