July 6, 20251 yr 3 hours ago, Karla Sleutel said: Isn't the minimum requirement chromium 138? Version 138 is required for the fix; the bug goes back earlier though: Quote Type confusion in V8 in Google Chrome prior to 138.0.7204.96 allowed a remote attacker to perform arbitrary read/write via a crafted HTML page. 7 hours ago, EliraFriesnan said: Initial release September 2, 2008 Good catch. Google is being tight-lipped on exactly when this vulnerability crept in. I doubt it goes all the way back to 2008, though. Today's V8 looks nothing like the original. I believe (and should have said) versions prior to the V8 optimizer are not vulnerable. I suspect 360EE (and Kafan MiniBrowser) aren't vulnerable because the option to turn off the optimizer isn't there (presumably because there's nothing to turn off), but I can't be sure with the limited info we have.
July 7, 20251 yr 16 hours ago, Mathwiz said: Version 138 is required for the fix; the bug goes back earlier though That was clear, but from what they tell, looks like the patch is intended to be applied only to 138+. Who would write a patch for the old 132, while we are at 140+ already?
July 7, 20251 yr You are right. You need version 138 or above to get the patch. If folks don't want to update, the patch is unavailable to them. For those folks, the only safe option is to turn off the V8 optimizer as described previously. I suppose, in theory, someone skilled in building Chromium could apply the patch to earlier versions, but I can't imagine anyone would do so, unless there were a very popular old version that many folks were reluctant to update from.
July 7, 20251 yr So has Win32ss engineered the patch for Supermium, even though it's only at Chromium 132? It is based on the ESR version, which should surely be able to have the patch applied?
July 8, 20251 yr So it can read memory from Supermium itself right, not crash other programs by writing to their memory? I'd be more worried if it could crash my PC since I run as administrator. Could one really make a gain out of this reliably? Memory addresses change.
July 8, 20251 yr 18 hours ago, j7n said: So it can read memory from Supermium itself right, not crash other programs by writing to their memory? I'd be more worried if it could crash my PC since I run as administrator. Could one really make a gain out of this reliably? Memory addresses change. Then it's a good idea to use the patched ungoogled for Server 2008 R2. No one knows and no one can guarantee how good and when the old 132 Supermium will (ever?) be patched for that serious vulnerability. https://github.com/e3kskoy7wqk/Chromium-for-windows-7/releases/tag/ungoogled-chromium_138.0.7204.96 Edit/ They say it's been patched in R5. But in the article they say the patch is for 138+! Contradictory. https://github.com/win32ss/supermium/releases/tag/v132-r5 Edited July 8, 20251 yr by Karla Sleutel
July 8, 20251 yr I think we have to take Shane's word for it that the patch has been applied to Supermium 132. As I said earlier, it's an ESR version, which surely should be capable of having the patch applied to it, as it should be fully supported until the next ESR version is released. I'm not sure how we can test whether the patch has been applied successfully or not.
July 12, 20251 yr We need a "benign exploit" page (a page that triggers the bug but doesn't do anything harmful) to test for this vulnerability. We had one for the WebP vulnerability.
July 23, 20251 yr New security patched release. Supermium 132.0.6834.226 R5.01 "The only substantial change in this release is a patch for vulnerabilities CVE-2025-8010 (CVE-2025-8011 is not applicable to M132) and CVE-2025-6558."
July 23, 20251 yr 13 hours ago, Dave-H said: (CVE-2025-8011 is not applicable to M132) Could this be sufficient proof that the previous patch for 138+ was also not applicable to M132?
July 24, 20251 yr I don't see why it would be, they are different exploits. I'm sure win32ss knows what needs patching and what doesn't.
July 29, 20251 yr On 7/24/2025 at 2:44 AM, Dave-H said: I don't see why it would be, they are different exploits. Because the previous exploit patch was also intended for a much higher core version, Namely, 138+.
July 29, 20251 yr Well, I really don't know, but presumably win32ss does! Surely the current ESR version has to be patched until it's superseded, if it's vulnerable, or there's no point in having it. That is 132 as far as I'm aware.
August 12, 20251 yr Hi I have Supermium last version, passwords not saved, password manager empty, no offer to save passwords. Is that normal for this version. Thanks. Edit: Solved by deleting the profile and importing csv file Edited August 14, 20251 yr by kwisomialbert Solved
August 17, 20251 yr On 8/13/2025 at 3:10 AM, kwisomialbert said: Hi I have Supermium last version, passwords not saved, password manager empty, no offer to save passwords. Is that normal for this version. Thanks. Edit: Solved by deleting the profile and importing csv file I never used password manager ,because it will makes me forget passwords...
Create an account or sign in to comment