채팅하기
Loader
연결을 설정 중입니다. 연결하는 동안 잠시 기다려 주십시오.

크롬 브라우저 파일 리더 취약점 (CVE-2019-5786)

구글 크롬은 GMS 운영 체제를 실행하는 Zebra 장치와 함께 제공되는 무료 인터넷 브라우저입니다.

On February 27th, 2019, Google announced it had uncovered a high-risk vulnerability within the browser, identified as CVE-2019-5786. A malicious actor could exploit the memory management within the Chrome FileReader, using Flash as the first exploit in a chain. There have been reports of active exploitation. Per Google: 

We strongly believe this vulnerability may only be exploitable on Windows 7 due to recent exploit mitigations added in newer versions of Windows. To date, we have only observed active exploitation against Windows 7 32-bit systems.

Google issued a new Chrome release on March 1st to address this vulnerability. Additional information about the release can be found on Google's site.  

Zebra strongly recommends all customers running Chrome ensure their devices have automatically downloaded the latest Chrome release (72.0.3626.121 or later) and that devices have been restarted to apply the update. While most Chrome updates occur automatically, a system restart is required in this case. Additionally, devices where automatic updates have been disabled will need to be manually updated. 


Google has reported a second vulnerability related to Microsoft Windows to Microsoft. Per Google:

The unpatched Windows vulnerability can still be used to elevate privileges or, combined with another browser vulnerability, to evade security sandboxes. Microsoft have told us they are working on a fix.

Zebra는 권장 패치에 대한 알림을 받는 대로 이 영역에 정보를 계속 게시할 것입니다.

영향을 받는 제품

Google 크롬 브라우저 소프트웨어 v. 72.0.3626.120 또는 그 이전을 실행하는 모든 Zebra 장치.

Disclaimer: Zebra makes every attempt to release security updates on or about the time that Google releases its respective security bulletin. However, delivery time of security updates may vary depending on the region, product model, and third party software suppliers. Under some circumstances, the OS must be updated to the latest maintenance release prior to installing the security updates. Individual product updates will provide specific guidance.

달리 명시되지 않는 한, 새로 보고된 문제로부터 의한 적극적인 고객 착취 또는 남용에 대한 보고는 없었습니다.



Zebra Technologies 제품의 잠재적인 보안 문제를 알고 있습니까?