Adobe and Google Partner to Bolster Flash's Defence Against Zero-Day Attacks

Advertisement
By Manish Singh | Updated: 20 July 2015 12:20 IST
Adobe Flash, the veteran media player that has earned a name for itself due to its security vulnerabilities as much as its abilities, is back in the news - but this time, for a good reason. Adobe has revealed that it worked with Google's Project Zero to patch the vulnerabilities discovered in the aftermath of a security breach of the Hacking Team.

But this isn't a regular security patch, Adobe notes. The company says that with the help of Google's security research team, it has managed to make structural changes to the way its program interacts with an operating system. The changes, Adobe claims, will significantly reduce the number of attacks against Flash Player.

One of the key changes the company made to Flash was to isolate different types of memory contents, which prevents them from interacting with each other. It did so by introducing a new partition to the heap, chunk of memory that's allocated to programs at run time. Another thing the company has introduced in Flash is the requirement to possess a validation key before any changes could be made to Vector objects - the go-to destination for hackers. The company has explained all the changes in depth via a blog post.

The patch is live in the Flash version dubbed v18.0.0.209 in Google Chrome, which started to seed late last week. You can check the Flash version inside the Chrome installed on your machine by visiting about:version inside the browser. If the Flash version isn't up to date, you can manually update your browser. You can do so by visiting chrome://chrome.

Advertisement

If the operating system installed in your computer is of 64-bit architecture, the company advises you to install the 64-bit build of Chrome, as in it, there are more memory addresses. "It's worth noting that this defence is much more powerful in a 64-bit build of Flash, because of address space limitations of 32-bit processes," it notes.

Advertisement

"It's a cat-and-mouse-game, but we'll be looking out for attackers' attempts to adapt, and devising further mitigations based on what we see," Google researchers note in the blog post. "Perhaps more importantly, we're also devising a next level of defences based on what we expect we might see. Our partitioning mitigation is far from finished. We'll be analysing object types to see what else might benefit from partitioning, and moving forward incrementally."

While it's a welcome move, at this point there is no guarantee whether tech giants will show any mercy towards Adobe's media player. The likes of Mozilla have already blocked Flash from some of their flagship products and services. Earlier this month, Facebook's new chief security officer announced that he wants to "set a date to kill Flash for once and all."

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Further reading: Adobe, Flash, Flash Player, Google, Project Zero
Advertisement

Related Stories

Popular Mobile Brands
  1. Vivo S50, S50 Pro Mini With Snapdragon Chips Launched at These Prices
  2. Pixel 10 Series Gets Price Cuts During Google's End of Year Sale: See Offers
  3. Mrs Deshpande OTT Release Date: Madhuri Dixit's Starrere to Premiere on This Date
  4. MacBook Air (2025) With M4 Chip Available at This Discounted Price
  5. Motorola Edge 70 With 5,000mAh Battery Launched in India at This Price
  6. OnePlus 15R Storage Options Leaked: Here's How Much It Might Cost in India
  7. Logitech MX Master 4 Launches in India With These Features
  8. RAM Crisis 2026: 16GB Phones Out, 4GB Models Making a Comeback
  9. Redmi Note 15 5G Chipset Revealed Ahead of January 6 India Launch
  10. Oppo Reno 15c With Snapdragon 7 Gen 4 SoC Launched at This Price
  1. Redmi Note 15 5G Chipset Confirmed Ahead of January 6 Launch in India: Expected Features, Specifications
  2. Lenovo Idea Tab Plus Launched in India With 12.1-Inch Display, 10,200mAh Battery: Price, Specifications
  3. The End of 16GB RAM Phones? AI Boom Forces Smartphone Makers to Bring Back 4GB Models
  4. Xiaomi 17 Ultra Tipped to Launch Alongside Redmi Turbo 5 Series, New Wearables
  5. Mrs Deshpande OTT Release Date: Madhuri Dixit’s Psychological Thriller Premieres on This Date
  6. Knives Out Now Streaming on Lionsgate Play: What You Need to Know
  7. The Copenhagen Test OTT Release Date: When and Where to Watch it Online?
  8. Tell Me Softly Out on OTT: Everything You Need to Know About This Spanish Teen Romance Film
  9. Vivo S50 Pro Mini Launched With Snapdragon 8 Gen 5 SoC, Vivo S50 Tags Along: Price, Specifications
  10. Clair Obscur: Expedition 33 Gets New 'Thank You' Update After Winning at The Game Awards
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.