Close Menu
Best in TechnologyBest in Technology
  • News
  • Phones
  • Laptops
  • Gadgets
  • Gaming
  • AI
  • Tips
  • More
    • Web Stories
    • Global
    • Press Release

Subscribe to Updates

Get the latest tech news and updates directly to your inbox.

What's On

Still Using Windows 10? Here’s How to Get Another Year of Updates for Free

31 July 2025

Oppo K13 Turbo, K13 Turbo Pro India Launch Timeline Leaked

31 July 2025

The Grave Long-Term Effects of the Gaza Malnutrition Crisis

31 July 2025
Facebook X (Twitter) Instagram
Just In
  • Still Using Windows 10? Here’s How to Get Another Year of Updates for Free
  • Oppo K13 Turbo, K13 Turbo Pro India Launch Timeline Leaked
  • The Grave Long-Term Effects of the Gaza Malnutrition Crisis
  • Samsung Galaxy S26 Pro, Galaxy S26 Edge Could Bring Battery Improvements Over Their Predecessors
  • Samsung Galaxy Book 4 Edge Price (31 Jul 2025) Specification & Reviews । Samsung Laptops
  • Time Flies Review – A Short-lived Buzz
  • The Kremlin’s Most Devious Hacking Group Is Using Russian ISPs to Plant Spyware
  • Qualcomm Said to be Developing Another High-End Chipset; Could Offer Snapdragon 8 Elite-Level Performance
Facebook X (Twitter) Instagram Pinterest Vimeo
Best in TechnologyBest in Technology
  • News
  • Phones
  • Laptops
  • Gadgets
  • Gaming
  • AI
  • Tips
  • More
    • Web Stories
    • Global
    • Press Release
Subscribe
Best in TechnologyBest in Technology
Home » Apple and Google Just Patched Their First Zero-Day Flaws of the Year
News

Apple and Google Just Patched Their First Zero-Day Flaws of the Year

News RoomBy News Room31 January 20243 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
Share
Facebook Twitter LinkedIn Pinterest Email

Later in January, Google released Chrome 121 to the stable channel, fixing 17 security issues, three of which are rated as having a high impact. These include CVE-2024-0807, a use-after-free flaw in WebAudio, and CVE-2024-0812, an inappropriate implementation vulnerability in accessibility. The final high-impact vulnerability is CVE-2024-0808, an integer underflow in WebUI.

Obviously, these updates are important, so check and apply them as soon as you can.

Microsoft

Microsoft’s January Patch Tuesday squashes nearly 50 bugs in its popular software, including 12 remote code execution (RCE) flaws.

No security holes included in this month’s set of updates are known to have been used in attacks, but notable flaws include CVE-2024-20677, a bug in Microsoft Office that could allow attackers to create malicious documents with embedded FBX 3D model files to execute code.

To mitigate this vulnerability, the ability to insert FBX files has been disabled in Word, Excel, PowerPoint, and Outlook for Windows and Mac. Versions of Office that had this feature enabled will no longer have access to it, Microsoft said.

Meanwhile, CVE-2024-20674 is a Windows Kerberos security feature bypass vulnerability rated as critical with a CVSS score of 8.8. In one scenario for this vulnerability, the attacker could convince a victim to connect to an attacker-controlled malicious application, Microsoft said. “Upon connecting, the malicious server could compromise the protocol,” the software giant added.

Mozilla Firefox

Hot on the heels of its market-dominant competitor Chrome, Mozilla’s Firefox has patched 15 security flaws in its latest update. Five of the bugs are rated as having a high severity, including CVE-2024-0741, an out-of-bounds write issue in Angle that could allow an attacker to corrupt memory, leading to an exploitable crash.

An unchecked return value in TLS handshake code tracked as CVE-2024-0743 could also cause an exploitable crash.

CVE-2024-0755 covers memory safety bugs fixed in Firefox 122, Firefox ESR 115.7, and Thunderbird 115.7. “Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code,” Mozilla said.

Cisco

Enterprise software giant Cisco has patched a vulnerability in multiple Cisco Unified Communications and Contact Center Solutions products that could allow an unauthenticated, remote attacker to execute arbitrary code on an affected device.

Tracked as CVE-2024-20253 and with a whopping CVSS score of 9.9, Cisco said an attacker could exploit the vulnerability by sending a crafted message to a listening port of an affected device.

“A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system with the privileges of the web services user,” Cisco said. “With access to the underlying operating system, the attacker could also establish root access on the affected device,” it warned.

SAP

SAP has issued 10 new security fixes as part of its January Security Patch Day, which includes several issues with a CVSS score of 9.1. CVE-2023-49583 is an escalation-of-privilege issue in applications developed through SAP Business Application Studio, SAP Web IDE Full-Stack, and SAP Web IDE for SAP HANA.

Meanwhile, CVE-2023-50422 and CVE-2023-49583 are escalation-of-privilege issues in SAP Edge Integration Cell.

Another notable flaw is CVE-2024-21737, a code injection vulnerability in SAP Application Interface Framework, which has a CVSS score of 8.4. “A vulnerable function module of the application allows an attacker to traverse through various layers and execute OS commands directly,” security firm Onapsis said. “Successful exploits can cause considerable impact on confidentiality, integrity, and availability of the application.”

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleHuawei Mate 70 Models Tipped to Compete With Upcoming iPhone 16 Series
Next Article Razer Blade 14 gaming laptop with an RTX 3080 Ti is $1,500 off

Related Articles

News

Still Using Windows 10? Here’s How to Get Another Year of Updates for Free

31 July 2025
News

The Grave Long-Term Effects of the Gaza Malnutrition Crisis

31 July 2025
News

The Kremlin’s Most Devious Hacking Group Is Using Russian ISPs to Plant Spyware

31 July 2025
News

Donald Trump’s New Crypto Bible Is Everything the Industry Ever Wanted

31 July 2025
News

The Inside Story of Eric Trump’s American Bitcoin

31 July 2025
News

Join Us for WIRED’s AI Power Summit

31 July 2025
Demo
Top Articles

ChatGPT o1 vs. o1-mini vs. 4o: Which should you use?

15 December 2024103 Views

Costco partners with Electric Era to bring back EV charging in the U.S.

28 October 202495 Views

Oppo Reno 14, Reno 14 Pro India Launch Timeline and Colourways Leaked

27 May 202582 Views

Subscribe to Updates

Get the latest tech news and updates directly to your inbox.

Latest News
Gaming

Time Flies Review – A Short-lived Buzz

News Room31 July 2025
News

The Kremlin’s Most Devious Hacking Group Is Using Russian ISPs to Plant Spyware

News Room31 July 2025
Phones

Qualcomm Said to be Developing Another High-End Chipset; Could Offer Snapdragon 8 Elite-Level Performance

News Room31 July 2025
Most Popular

The Spectacular Burnout of a Solar Panel Salesman

13 January 2025125 Views

ChatGPT o1 vs. o1-mini vs. 4o: Which should you use?

15 December 2024103 Views

Costco partners with Electric Era to bring back EV charging in the U.S.

28 October 202495 Views
Our Picks

Samsung Galaxy S26 Pro, Galaxy S26 Edge Could Bring Battery Improvements Over Their Predecessors

31 July 2025

Samsung Galaxy Book 4 Edge Price (31 Jul 2025) Specification & Reviews । Samsung Laptops

31 July 2025

Time Flies Review – A Short-lived Buzz

31 July 2025

Subscribe to Updates

Get the latest tech news and updates directly to your inbox.

Facebook X (Twitter) Instagram Pinterest
  • Privacy Policy
  • Terms of use
  • Advertise
  • Contact Us
© 2025 Best in Technology. All Rights Reserved.

Type above and press Enter to search. Press Esc to cancel.