Google Discloses Windows 10 Bug Under 'Active Attack'; Microsoft Working on Fix

Advertisement
By Akhil Arora | Updated: 2 November 2016 10:55 IST
Highlights
  • Windows 10 vulnerability is win32k.sys system call
  • Google said it's being "actively exploited"
  • Microsoft is unhappy with Google going public before patch

On Monday, Google’s Threat Analysis Group published details of a critical vulnerability in Microsoft’s Windows 10 that allows hackers to escape security sandboxes by using a system call with win32k.sys. The reason Google chose to go public with this knowledge is because it believes the vulnerability is being “actively exploited”.

Google had informed both Adobe and Microsoft of zero-day vulnerabilities only 10 days ago on October 21. While Adobe has already issued a patch for Flash – which is available via auto-updater or manual install – Microsoft has yet to send out an update for Windows 10 that blocks the use of this mechanism. And hence, as you’d expect, Microsoft isn’t happy with the disclosure.

“We believe in coordinated vulnerability disclosure, and today’s disclosure by Google puts customers at potential risk,” Microsoft conveyed to VentureBeat via a statement. “Windows is the only platform with a customer commitment to investigate reported security issues and proactively update impacted devices as soon as possible. We recommend customers use Windows 10 and the Microsoft Edge browser for the best protection.”

Advertisement

Google’s short disclosure period for "vulnerabilities under active attack" came into effect in May 2013, bringing it down from 60 days to just a week. Google noted that 7 days might be “an aggressive timeline and may be too short for some vendors to update their products” but it justified the urgency of its disclosures by saying that it’s still enough time to inform users and give some advice.

Advertisement

Issuing a fix for a web plug-in such as Adobe Flash is obviously much easier than patching an operating system, which is why Google’s policy for vulnerabilities under active attack has remained controversial. For now, you should check to see Flash is updated and install Windows patches the moment Microsoft issues them.

 

Catch the latest from the Consumer Electronics Show on Gadgets 360, at our CES 2026 hub.

Advertisement

Related Stories

Popular Mobile Brands
  1. CNAP vs Truecaller: Which Is Better at Identifying Spam Calls?
  2. Samsung Galaxy S26 Series Roundup: Everything That We Know So Far
  3. Quantum Haloscope Sharpens the Search for Dark Matter Axions at Higher Frequencies
  4. Rare Interstellar Object 3I/ATLAS Fails Alien Test, Scientists Say
  1. Quantum Haloscope Sharpens the Search for Dark Matter Axions at Higher Frequencies
  2. Rare Interstellar Object 3I/ATLAS Fails Alien Test, Scientists Say
  3. CNAP vs Truecaller: How India’s Official Caller ID System Differs From the Popular App
  4. Prayagraj Ki Love Story Set to Stream Soon on Hungama OTT
  5. Mask OTT Release Date: When and Where to Watch This Action-Packed Thriller Online?
  6. New Year 2026 Custom Greetings: 5 Best AI Prompts for ChatGPT, Gemini, and Other AI Tools
  7. NASA’s Chandra Spots Champagne Cluster Formed by a Massive Galaxy Collision
  8. NASA’s Curiosity Rover Sends Stunning Sunrise-and-Sunset Holiday Postcard from Mars
  9. Oppo Find X9s Key Specifications Leaked Again; Might Also Launch in India
  10. Redmi Turbo 5, Redmi Turbo 5 Pro to Be Equipped With Upcoming MediaTek Dimensity Chips, Tipster Claims
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.