Remove 07
article thumbnail

Google paid over $130K in bounty rewards for the issues addressed with the release of Chrome 93

Security Affairs

Watch out for upcoming Chrome and Chromium blog posts about new features and big efforts delivered in 93.” The most severe flaw, tracked as CVE-2021-30606, is a use-after-free in Blink that was reported by 360 Alpha Lab researchers reported by Nan Wang ( @eternalsakura13 ) and koocola ( @alo_cook ) of 360 Alpha Lab.

article thumbnail

Dirty Pipe Linux flaw allows gaining root privileges on major distros

Security Affairs

In a blog post, the researcher explained that he discovered the flaw while investigating corrupt access log files for one of its customers. The CVE-2022-0847 vulnerability allows overwriting data in arbitrary read-only files, which could lead to privilege escalation because unprivileged processes can inject code into root processes.