HomeSecurityNew SQLite vulnerabilities affect Chrome and other programs

New SQLite vulnerabilities affect Chrome and other programs

vulnerabilities New vulnerabilities have been found in the software SQLite. The result was that many applicationsthat use SQLite as a component of software packages were affected.

SQLite is a database management system. Many popular programs use it. Some of these programs are: Google Chrome, Mozilla Firefox, Windows 10 and others.

The vulnerabilities were discovered by researchers from Tencent Blade Team and are called “Magellan 2.0.” A year ago, the original vulnerabilities, Magellan 1.0 SQLite, were discovered.

Like the Magellan 1.0 vulnerabilities, the Magellan 2.0 ones affect all programs that use SQLite in their software.

According to the researchers, these bugs allow attackers to exploit remote code execution in the Chromium rendering process.

The researchers said: “SQLite is a well-known database management system, so it is widely used in all modern operating systems and software. Therefore, these vulnerabilities have a wide scope of influence. SQLite and Google had confirmed the existence of the vulnerabilities and had fixed these vulnerabilities. We will not disclose details of the vulnerabilities at this time but we are pushing other vendors to fix this issue as soon as possible.”

New SQLite vulnerabilities affect Chrome and other programs

Tencent's research team exploited the vulnerabilities and found that it could remotely execute commands in Google Chrome (when WebSQL was enabled in the browser).

This is a major security issue as attackers can use it to completely compromise a computer.

“If you are using software that uses SQLite as a core component (not up to date with the latest December 2019 version) and supports external SQL queries, or if you are using Chrome prior to version 79.0.3945.79 (with WebSQL enabled), you are likely to be affected. Other devices, such as PC/Mobile/IoT devices.”

Tencent notified Google and SQLite about the Magellan 2.0 vulnerabilities on November 16, 2019. However, the company has not discovered any exploitation of the vulnerabilities by hackers.

All software that uses SQLite should immediately install the latest version to stay secure.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS