Search

Google Discloses Windows 10 Bug Under 'Active Attack'; Microsoft Working on Fix

Advertisement
Highlights
  • Windows 10 vulnerability is win32k.sys system call
  • Google said it's being "actively exploited"
  • Microsoft is unhappy with Google going public before patch
Google Discloses Windows 10 Bug Under 'Active Attack'; Microsoft Working on Fix

On Monday, Google’s Threat Analysis Group published details of a critical vulnerability in Microsoft’s Windows 10 that allows hackers to escape security sandboxes by using a system call with win32k.sys. The reason Google chose to go public with this knowledge is because it believes the vulnerability is being “actively exploited”.

Google had informed both Adobe and Microsoft of zero-day vulnerabilities only 10 days ago on October 21. While Adobe has already issued a patch for Flash – which is available via auto-updater or manual install – Microsoft has yet to send out an update for Windows 10 that blocks the use of this mechanism. And hence, as you’d expect, Microsoft isn’t happy with the disclosure.

“We believe in coordinated vulnerability disclosure, and today’s disclosure by Google puts customers at potential risk,” Microsoft conveyed to VentureBeat via a statement. “Windows is the only platform with a customer commitment to investigate reported security issues and proactively update impacted devices as soon as possible. We recommend customers use Windows 10 and the Microsoft Edge browser for the best protection.”

Google’s short disclosure period for "vulnerabilities under active attack" came into effect in May 2013, bringing it down from 60 days to just a week. Google noted that 7 days might be “an aggressive timeline and may be too short for some vendors to update their products” but it justified the urgency of its disclosures by saying that it’s still enough time to inform users and give some advice.

Issuing a fix for a web plug-in such as Adobe Flash is obviously much easier than patching an operating system, which is why Google’s policy for vulnerabilities under active attack has remained controversial. For now, you should check to see Flash is updated and install Windows patches the moment Microsoft issues them.

For the latest tech news and reviews, follow Gadgets 360 on X, Facebook, WhatsApp, Threads and Google News. For the latest videos on gadgets and tech, subscribe to our YouTube channel. If you want to know everything about top influencers, follow our in-house Who'sThat360 on Instagram and YouTube.

 
Show Full Article
Please wait...
Advertisement

Related Stories

Popular Mobile Brands
  1. OTT Releases This Week: The Royals, The Diplomat, Robinhood, and More
  2. Oppo Reno 14, Reno 14 Pro RAM and Storage Options Revealed
  3. Vivo Y300 GT With 7,620mAh Battery, 90W Fast Charging Launched
  4. Vivo 30 Series With Vivo S30 Pro Mini Variant to Launch Later This Month
  5. OnePlus 13s With Customisable 'Plus Key' Teased Ahead of Launch in India
  6. Samsung Galaxy S25 Edge Key Features, Accessories Leak Online
  7. Vivo V50 Elite Edition Will Reportedly Launch in India on This Date
  8. You Can Now Use Adobe Express, Perplexity and Other AI Apps in Slack
  9. Apple Is Reportedly Developing These Chips for Mac Models, AI Servers
  1. Lenovo Legion 9i With Intel Core Ultra 9 Chip, Up to GeForce RTX 5090 Laptop GPU Announced
  2. Samsung's Tri-Fold Phone Tipped to Use Silicon-Carbon Battery; Could Share Features With Galaxy Z Fold 7
  3. LockBit Ransomware Group Reportedly Suffers Data Breach, Extortion Tactics Revealed
  4. Vivo V50 Elite Edition India Launch Date Leaked; Design Said to Differ From Vivo V50 Model
  5. Samsung Galaxy S25 Edge Key Features, Accessories Leak Online Ahead of May 13 Launch
  6. Slack Adds Adobe Express, Perplexity and 23 New AI Apps to Its Marketplace
  7. Samsung Galaxy S25 FE Tipped to Use a MediaTek Dimensity 9400 SoC
  8. Boat Storm Infinity Plus Smartwatch With Up to 20 Days Battery Launched in India: Price, Specifications
  9. Whoop MG With Medical Grade ECG Readings, Blood Pressure Insights Launched Alongside Refreshed Whoop 5.0
  10. Meta Said to Consider Stablecoin Use for International Creator Payouts
Gadgets 360 is available in
Download Our Apps
App Store App Store
Available in Hindi
App Store
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.
Trending Products »
Latest Tech News »