Picked up by security specialist Sophos, Google has quietly issued a warning that Chrome has a critical security flaw across Windows, Mac and Linux and it urges users to upgrade to the latest version of the browser (81.0.4044.113). Interestingly, at the time of publication, Google is also keeping the exact details of the exploit a mystery.
In a blog post, all Google divulges is the codename for the exploit (CVE-2020-6457) and a vague description: “Use after free in speech recognizer”. Do some digging, however, and you will find the exploit has been marked as 'Reserved' by the US government’s National Vulnerability Database.
Shedding some light upon this, however, is Sophos which explains:
“[I]n some cases, use-after-free bugs can allow an attacker to change the flow of control inside your program, including diverting the CPU to run untrusted code that the attacker just poked into memory from outside, thereby sidestepping any of the browser’s usual security checks or “are you sure” dialogs. That’s the most serious sort of exploit, known in the jargon as RCE, short for remote code execution, which means just what it says – that a crook can run code on your computer remotely, without warning, even if they’re on the other side of the world.”