Chrome 155 Patches 247 Flaws, Four Critical
Google is giving you 247 fresh reasons to finally hit that update button for Chrome on Windows, macOS, and Linux. The massive patch drops the hammer on four critical use-after-free bugs and 53 high-severity issues. While memory-safety flaws like these are practically an open invitation for remote code execution, nobody has RSVP’d to exploit them in the wild just yet.
Interestingly, an Anthropic researcher sniffed out two of the critical flaws with Claude’s help. Finally, AI is doing the digital dishes instead of just generating weird hands.
Mobile users aren’t off the hook, either. Android’s update mirrors the desktop fixes, and the iOS app also got a tune-up.
On desktop, navigate to Help > About Google Chrome or Chrome > About Google Chrome and actually relaunch your browser. IT admins, verify your endpoints are patching instead of blindly trusting background updates. The rollout is gradual.
Your precious collection of 142 open tabs doesn’t grant you a patching exemption.
Android’s October Patches Go Beyond the OS Upgrade
Google’s October Android patches are out, sweeping up 25 unique flaws—including seven critical bugs lurking in Android 17 and older releases. The nastiest let attackers trigger remote denial of service and local privilege escalation without you ever touching your screen. Thankfully, Google hasn’t spotted active exploitation.
Pixels get six additional fixes—three critical—plus model-dependent TLC for vanishing keyboards, distorted VoIP ringtones, and upside-down photos. Yes, a security patch that literally teaches your camera which way is up.
Meanwhile, Samsung’s package brings Galaxy-specific fixes for flaws letting local attackers execute code. Manually update Samsung Internet to 30.0.5.24, too; a One UI upgrade won’t magically deliver its separate script-injection patch.
Verify your patch dates: Oct. 1 covers the main bulletin, while Pixels need Oct. 5. Rollouts vary, so IT teams should actually audit fleet patch levels.
Android 17 is a version number, not a permission slip to skip patches.
Dell Server Update Flaw Exposes Root Access
Dell disclosed five System Update flaws, including a vulnerability that could let unauthenticated remote attackers execute code as root.
Because DSU manages system-level updates with elevated privileges, a compromise could give attackers broad server control, although Dell reports no active exploitation.
What concerns me is that root access through DSU could let an attacker disable or alter the security controls designed to detect their activity.
Upgrade Dell System Update to the latest version and review affected servers for unusual DSU activity, privilege escalation, or unexpected system changes.
Rejetto HFS Vulnerability Gives Attackers Admin Access
Attackers are actively exploiting a Rejetto HFS flaw that can give unauthenticated attackers administrator access and remote code execution.
The vulnerability stems from a predictable session-signing key that attackers can recover to forge a valid administrator session.
Threat actors can effectively create their own administrator access without first stealing legitimate credentials.
Upgrade HFS and review exposed servers for unauthorized administrator sessions or unexpected configuration changes.
8.8 Million Hit by Denmark Registry Data Exposure
Personal data tied to about 8.8 million people was accessed without authorization through Denmark’s Central Person Register, exposing names, addresses, and CPR numbers.
Investigators traced the automated searches to a private company’s legitimate registry access rather than it being a direct breach of the CPR system.
This incident shows a potential blind spot where organizations monitor who has permission but not how those permissions are being used.
Set usage thresholds for sensitive systems and alert on unusual query volumes or access patterns.
South Korea Probes Wave of Bank Data Breaches
The South Korean President ordered an investigation after cyberattacks exposed data from tens of thousands of financial customers.
Authorities are examining possible AI involvement, although investigators have not confirmed that AI tools played a role in the attacks.
I wouldn’t assume AI made these attacks more sophisticated until investigators determine how it was used. Finding an AI tool doesn’t mean it played a meaningful role in the attack.
Hunt for unusual scanning activity against internet-facing systems and compare suspicious IPs and attack patterns with financial-sector threat intelligence.
Malicious Custom GPTs Push ClickFix Malware
Threat actors are using malicious Custom GPTs to trick Windows users into running PowerShell commands that install a remote access trojan.
The PowerShell command launches a multi-stage infection chain that establishes persistence.
Using Custom GPTs gives ClickFix attackers another way to reach victims through a platform they may already consider legitimate.
Alert when PowerShell launches msiexec and hunt for unexpected scheduled tasks or Run key changes.
Can Your Defenses Stop ClickFix?
ClickFix attacks trick users into running malicious commands through legitimate tools like PowerShell, making behavioral detection essential.
How to protect against ClickFix attacks:
- Control command execution by treating command-based verification as malicious and restricting PowerShell access to users who need it.
- Monitor suspicious activity with script logging and alerts for unusual process chains, scheduled tasks, and Run key changes.
- Test your defenses with attack simulation tools and validate incident response plans against realistic ClickFix attack scenarios.
The bigger ClickFix question for security teams is whether existing controls can interrupt the attack after an employee follows the initial instructions.