Chrome Exploits — zero-day remediation

Mr. Cyber
3 min readApr 15, 2022
Chrome Exploits — zero-day

1. Update Google Chrome

Check pending updates

  1. On your computer, open Chrome.

2. At the top right, click on the “More” icon.

3. If an update is pending, the icon will be colored: <span style=”color:Green”>Green</span>: An update was released less than 2 days ago. <span style=”color:Orange”>Orange</span>: An update was released about 4 days ago. <span style=”color:Red”>Red</span>: An update was released at least a week ago.

Update

  1. On your computer, open Chrome.
  2. At the top right, click on the More icon.
  3. Click Update Google Chrome. Important: If you can’t find this button, you’re on the latest version.
  4. Click Relaunch.

The browser saves your opened tabs and windows and reopens them automatically when it restarts. Your Incognito windows won’t reopen when Chrome restarts. If you would prefer not to restart right away, click Not now. The next time you restart your browser, the update will be applied.

2. Restrict Chrome Extensions

Description

Less secure apps don’t employ modern security standards and measures, such as OAuth. Using apps lacking in security measures increases the risk of accounts being compromised. Blocking these apps helps keep users and data safe.

Examples of apps that don’t support modern security standards include:

  • ​Native mail
  • Contacts, and calendar sync applications on older versions of iOS and macOS X
  • ​Some computer mail clients, such as older versions of Microsoft Outlook

Examples of apps that do support modern security standards are:

  • Gmail
  • Windows Mail
  • Office 365
  • Outlook for Mac
  • Instagram
  • PayPal
  • Amazon
  • Facebook
  • Basecamp

How to restrict Chrome Extensions

  1. Go to the Google Admin Panel

2. Go to Security — Configure security settings

3. Go to Less Secure Apps

4. Click on “Disabled access to less secure apps”.

5. Click on “Save”.

3. Chrome — How To Block Javascript

Through Chrome Settings

  1. Go to Javascript Settings

2. Change “Allowed (recommended)” to “Blocked”

3. (Optional) — Add trusted sites to “Allow” list

Using a Chrome Extention

  1. Go to Google Chrome Extensions

2. Search for a Javascript Blocker

3. Choose an extension that fits your security policies and click “Add to Chrome”

References

Google — Update Chrome

Google — Less Secure Apps

Block JS

--

--