Microsoft How We Unearthed A Critical Flaw In Chromeos And How Google Fixed It
ChromeOS is Google’s proprietary OS based on the open-source ChromiumOS, which itself is underpinned by Linux. Microsoft security researcher Jonathan Bar Or found the bug in the ChromiumOS Audio Server (CRAS), a service that routes audio to peripherals such as USB speakers and Bluetooth headsets. Or found a local memory corruption issue that could be remotely triggered by manipulating audio metadata, either in the browser or via Bluetooth. SEE: The 7 best cybersecurity certifications: Become a security expert “Attackers could have lured users into meeting these conditions, such as by simply playing a new song in a browser or from a paired Bluetooth device, or leveraged adversary-in-the-middle (AiTM) capabilities to exploit the vulnerability remotely,” he explains in a blogpost....