Google just patched the fifth zero-day exploit for Chrome this year

Google has released a security update for the Chrome browser to fix a zero-day vulnerability exploit that has been used by threat actors. This is the fifth time this year the company has had to issue a patch for one of these vulnerabilities, as reported by Bleeping Computer.

"Google is aware that an exploit for CVE-2024-4671 exists in the wild," the company said in a short advisory. It did not issue any specifics as to the nature of the real-world attack or the identity of the threat actors. This is common for Google, as it likes to wait until a majority of users have updated the software before announcing specific details.

We do know some stuff about the exploit. It’s being classified as a “high-severity issue” and as a “user after free” vulnerability. These bugs arise when a program references a memory location after it has been deallocated, leading to any number of serious consequences from a crash to a random execution of code. It looks like the CVE-2024-4671 vulnerability is attached to the visuals component that handles rendering and the display of content on the browser.

The exploit was discovered and reported to Google by an anonymous researcher. The fix is available for Mac, Windows and Linux and updates will continue to roll out to users over the coming days and weeks. Chrome updates automatically with security fixes, so users can confirm they are running the latest version of the browser by going to Settings and About Chrome. Users of Chromium-based browsers like Microsoft Edge, Brave, Opera and Vivaldi should also update to a new version as soon as they are available. 

As stated, this is the fifth of this type of flaw addressed by Google this year. I don’t mean “within the last calendar year.” I mean in 2024. Three were discovered back in March at the Pwn2Own hacking contest in Vancouver. This isn’t a record or anything. Google found and fixed five in one month back in 2020.

Zero-day exploits have been a constant thorn in Google’s side. These are a type of cyberattack that take advantage of an unknown or unaddressed security flaw in computer software, hardware or firmware. The company typically pays out big money for bug discoveries, as part of its Vulnerability Rewards Program.

This article originally appeared on Engadget at https://www.engadget.com/google-just-patched-the-fifth-zero-day-exploit-for-chrome-this-year-153723334.html?src=rss

Engadget Podcast: Is the iPad Pro M4 overkill?

As rumors foretold, Apple has revamped the iPad Pro with an M4 chip, tandem OLED screen and a thinner case. There's also a new Magic Keyboard that should deliver a more MacBook-like typing experience! In this week's episode, Cherlynn and Devindra discuss how Apple is shining a new light on tablets (which also includes the new iPad Air models) and reworking its vision of mobile computing. Does anyone really need the iPad Pro today? And could it be more compelling if iPadOS improves its multitasking capabilities? Also, we discuss the launch of Google's new mid-range phone, the Pixel 8a.


Listen below or subscribe on your podcast app of choice. If you've got suggestions or topics you'd like covered on the show, be sure to email us or drop a note in the comments! And be sure to check out our other podcast, Engadget News!

  • New iPad Pro with OLED and M4 processor, iPad Air and Apple Pencil announced at ‘Let Loose’ event – 1:04

  • Google announces Pixel 8a with 120Hz OLED screen and AI capability – 20:50

  • What the heck happed with Helldivers 2? – 28:31

  • Microsoft shuts down Tango Gameworks and Arkane Austin – 34:10

  • Hades 2 early access is out now – 42:01

  • Around Engadget: Steve Dent reviews Fujifilm X100 VI – 45:39

  • Working on – 48:38

  • Pop culture picks – 52:08

Hosts: Cherlynn Low and Devindra Hardawar
Producer: Ben Ellman
Music: Dale North and Terrence O'Brien

This article originally appeared on Engadget at https://www.engadget.com/engadget-podcast-ipad-pro-m4-113031564.html?src=rss

The Morning After: Apple apologizes for its iPad Pro ad that crushed human creativity

Apple has apologized for its Crush! ad, which sparked a furious backlash among artists, musicians, and other creators. AdAge reports Apple said the video “missed the mark,” and it has scrapped plans to run the commercial on TV. The video shows a series of musical instruments and other tools for human expression, including a guitar, drums, trumpet, amplifiers, record player, TV and much more being crushed to “All I Ever Need Is You” by Sonny and Cher. The crusher pulls up to reveal an iPad. Tonally, you could see how it could be misconstrued.

Apple is rumored to have more AI tricks planned for its next WWDC, while this new iPad Pro has a chip that boasts a lot of AI power, all with the looming threat of AI to creatives.

But — and imagine I’m using my indoor voice, here — it’s just an ad. However, Apple is such a huge company that it wields a huge amount of influence. And everyone is watching.

— Mat Smith

How to watch Google's I/O 2024 keynote

Nintendo is done paying Elon Musk for X integration on its consoles

Asteroids and Resident Evil join the World Video Game Hall of Fame

​​You can get these reports delivered daily direct to your inbox. Subscribe right here!

In a rambling interview, Twitter founder Jack Dorsey claimed Bluesky was “literally repeating all the mistakes” he made while running Twitter. Dorsey’s complaints seem to boil down to two issues. First, he never intended Bluesky to be an independent company, with its own board and stock and other vestiges of a corporate entity. Instead, his plan was for Twitter — as it was called — to be the first client to take advantage of the open-source protocol Bluesky created.

Dorsey also didn’t like Bluesky’s form of content moderation, and how it has occasionally banned users for things like using racial slurs in their usernames. A lot of this isn’t particularly surprising. If you’ve followed Dorsey’s public comments over the last couple years, he’s repeatedly said Twitter’s “original sin” was being a company beholden to advertisers.

Continue reading.

The US Food and Drug Administration (FDA) issued a Class I recall for the t:connect mobile app on iOS, which people with diabetes use to monitor and control an insulin pump. The FDA received 224 injury reports as of April 15. Insulin pumps, like the t:slim X2, automatically deliver insulin under the user’s skin at set intervals and whenever needed. The bug excessively drained power from the pump, meaning it could shut down without warning and before the user expected it to, leading to the under-delivery of insulin.

Continue reading.

TMA
Netflix

This simply sounds horrible.

Continue reading.

This article originally appeared on Engadget at https://www.engadget.com/the-morning-after-apple-apologizes-for-its-ipad-pro-ad-that-crushed-human-creativity-111523044.html?src=rss

Microsoft’s web-based mobile game store opens in July

In a couple of months, you'll be able to get Microsoft's mobile games from its own store. Xbox President Sarah Bond has revealed at the Bloomberg Technology Summit that the company is launching a web-based store where you can download its mobile games and get add-ons or in-app purchases at a discount. Bond said the company has decided to launch a browser-based store instead of an app to make it "accessible across all devices, all countries, no matter what" so that you don't get "locked to a single ecosystem."

Microsoft will only host its own games to start with, which means it will feature a lot of titles from Activision Blizzard. If you'll recall, it snapped up the gaming developer and publisher in a $70 billion deal that closed last year. You'll most likely find Candy Crush Saga, which has apparently generated $20 billion in revenue since it launched in 2012, and Call of Duty's mobile games in the first batch of titles available for download. Bond said that Minecraft may also be one of the first games you can get. 

An Xbox spokesperson told Bloomberg that this is "just the first step in [the company's] journey to building a trusted app store with its roots in gaming." Microsoft plans to open the app store to third-party publishers in the future, though it didn't share a timeline for that goal. 

The company first announced its intention to launch a gaming store for Android and iOS devices last year shortly before rules under the EU's Digital Markets Act became applicable. To comply with DMA rules, Apple and Google have to allow third-party app stores to be accessible on their platforms and to offer alternative billing systems for purchases. They're also compelled to allow app sideloading, which will be a massive change for Apple, a company known for its "walled garden" approach to business. 

Operators of third-party app stores will get to avoid some of the fees Google and Apple charge, but they'd still have to pay the companies for bypassing their mobile platforms' official stores. Both tech giants have already outlined how they're changing things up to comply with the DMA regulations. The companies' rivals found the changes they're making insufficient, however, prompting the European Commission to start investigating their compliance plans. 

This article originally appeared on Engadget at https://www.engadget.com/microsofts-web-based-mobile-game-store-opens-in-july-090044359.html?src=rss

Apple apologizes for its tone-deaf ad that crushed human creativity to make an iPad

Apple has reportedly apologized for its tone-deaf “Crush!” ad that sparked a furious backlash with artists, musicians and other creators. AdAge reports that Apple said the video “missed the mark” and has scrapped plans to run the cutesy-turned-cringey commercial on TV.

It’s clear that Apple intended for the ad to serve as a metaphor for all the myriad creative tools one has when they throw down $1,000 or more for a new iPad Pro. Run during Tuesday’s event, the video shows a series of musical instruments and other tools for human expression, including a guitar, drums, trumpet, amplifiers, record player, TV and much more. “All I Ever Need Is You” by Sonny & Cher soundtracks the clip.

Soon, it’s revealed that the objects are all sitting on an industrial crusher, which descends upon the scattered creative instruments, exploding in plumes of satisfyingly colorful smoke. But when the crusher pulls back up, we see that everything was transformed into a shiny new iPad Pro.

Creative objects arranged on a crusher.
Apple

A decade ago, this ad likely wouldn’t have been a big deal. But Apple’s marketers completely whiffed on the context of the moment. The ad comes weeks before Apple will take the stage at WWDC to announce its generative AI features that its investors have been salivating for.

Generative AI, as you may have heard, needs something to train on — and that means humans’ work. It learns from existing content to make algorithmically generated words, pictures, music, voices or who knows what else. It also has the capability to put those same creators — most of whom don’t have cushy jobs at Apple or other Big Five tech companies — out of work as corporations and consumers eagerly adopt the robots destined to put creators on the unemployment line.

Context is everything, and Apple failed spectacularly there. Its ad serves as a pitch-perfect metaphor for generative AI’s potential to crush human creation, turning us all into “prompt artists” who type words into text boxes to replace their years of training and experience. (Granted, generative AI has genuinely exciting applications, too, but much more needs to be made of the society-level chaos it can and will unleash.)

“Creativity is in our DNA at Apple, and it’s incredibly important to us to design products that empower creatives all over the world,” Tor Myhren, Apple VP of marketing communications, told AdAge. “Our goal is to always celebrate the myriad of ways users express themselves and bring their ideas to life through iPad. We missed the mark with this video, and we’re sorry.”

Hey, an apology means something. But we’ll see what tone Apple adopts next month when it rolls out the tools that set the stage for the apology in the first place. Something tells me that train is out of the station and will be plowing forward full steam, no matter how much creativity the company has in its DNA.

This article originally appeared on Engadget at https://www.engadget.com/apple-apologizes-for-its-tone-deaf-ad-that-crushed-human-creativity-to-make-an-ipad-211116524.html?src=rss

Get up to $450 off a Google Pixel Tablet when you trade in your old iPad or Android slab

Google has an offer for iPad owners who are curious about the Pixel Tablet. The company has a trade-in promotion that covers at least the cost of the Pixel Tablet for iPad owners — if not more, depending on which model you have. It works with Samsung tablets as well, but those trade-in values are lower. The Pixel Tablet costs $399 (without deals) for 128GB storage and no charging speaker dock.

The promo works with iPads as old as the sixth-generation model from six years ago. For that, Google will give you a surprising $399 — matching the Pixel Tablet’s base cost. That iPad model only cost $329 in 2018, so Google is overpaying by a lot for that one.

However, Google balances that with much worse offers for modern, high-end iPads. For example, the 12.9-inch iPad Pro with M2 chip (2022) only nets $450. Until this week (when the company launched a new iPad Pro and iPad Air), Apple sold that model for $1,099, so we don’t recommend that trade-in price. If you’re done with a high-end iPad from the last few years, you can likely sell it on places like eBay, Craigslist or Swappa for significantly more.

View of the Pixel Tablet on a shelf next to books and oddities.
Sam Rutherford for Engadget

The Pixel Tablet stands out from its Android-running competitors by working with a charging speaker base that lets the device double as a smart display, making it much more versatile. Engadget’s Cherlynn Low thought that part overshadowed its core functionality as a tablet. “As a smart display, the Pixel Tablet mostly shines. It has a useful dashboard, an easy-to-read interface and impressive audio quality,” she wrote in our full review.

The tablet has a 10.95-inch display with a 2,560 x 1,600 resolution (276 PPI) and runs on a Google Tensor G2 chip. It weighs slightly over a pound and is lighter than Android rivals like the Galaxy Tab S8 and OnePlus Pad. Its back has a nano-ceramic coating that gives it a premium, glass-like feeling that you may not expect from a $399 device.

Accessories are where the Pixel Tablet stands out the most. Google’s Pixel Tablet Case, sold separately for $79, has a built-in kickstand that makes the slate more versatile. “What I love about the kickstand-hanger-combo is that it allows you to place the Tablet pretty much anywhere,” Low wrote in Engadget’s review. “So when I want to hang it off a kitchen cabinet to follow along with a recipe video or keep watching Love Is Blind for example, I can. And though the 2,560 x 1,600 LCD panel isn’t as vibrant as the OLED on Samsung’s Galaxy Tabs, it still produced crisp details and colorful images.”

The star accessory is Google’s $129 charging speaker dock, which you can use without removing the kickstand case. This product transforms the tablet into a smart display, potentially voiding the need for other smart home control hubs. The speaker has impressive sound for its size, making it easier to hear its responses if you aren’t right next to it.

Google’s fine print notes that the trade-in value will be finalized after receiving the tablet, and it could be lower if it determines the condition doesn’t match what you selected during the trade-in process. The refund will be processed on the credit card you used to buy the Pixel Tablet (or through Google Store credit if you return your purchase during that time).

Follow @EngadgetDeals on Twitter and subscribe to the Engadget Deals newsletter for the latest tech deals and buying advice.

This article originally appeared on Engadget at https://www.engadget.com/get-up-to-450-off-a-google-pixel-tablet-when-you-trade-in-your-old-ipad-or-android-slab-192718892.html?src=rss

Alienware m16 R2 review: When less power makes for a better laptop

The Alienware m16 R2 is a rarity among modern laptops. That’s because normally after a major revamp, gadget makers like to keep new models on the market for as long as possible to minimize manufacturing costs. However, after its predecessor launched last year sporting a fresh design, the company reengineered the entire system again for 2024 while also limiting how big of a GPU can fit inside. So what gives? The trick is that by looking at the configurations people actually bought, Alienware was able to rework the m16 into a gaming laptop with a sleeker design, better battery life and a more approachable starting price, which is a great recipe for a well-balanced notebook.

There are so many changes on the m16 R2’s chassis it’s hard to believe it’s from the same line. Not only has Alienware gotten rid of the big bezels and chin from the R1, but the machine is also way more portable now. Weight is down more than 20 percent to 5.75 pounds (from 7.28 pounds) and it’s also significantly more compact with a depth of 9.8 inches (versus 11.4 inches before). For some style points, Alienware added RGB lighting around the perimeter of the touchpad. This result is a major upgrade for anyone who wants to take the laptop on the go. It fundamentally changes the system from something more like a desktop replacement to a portable all-rounder.

Critically, despite being smaller, the m16 R2 still has a great array of connectivity options. On its sides are two USB 3.2 Type-A ports, a microSD card reader, an Ethernet jack and a 3.5mm audio socket. Around back, there are two USB-C slots (one supports Thunderbolt 4 while the other has DisplayPort 1.4), a full-size HDMI 2.1 connector and a proprietary barrel plug for power. Generally, I like this arrangement as moving some ports to the rear of the laptop helps keep clutter down. That said, I wish Alienware had switched the placement of the Ethernet jack and one of the USB-C ports, as I find myself reaching for the latter much more often.

While it doesn't have support for HDR, the 16-inch display on the Alienware m16 R2 does have a speedy 240Hz refresh rate.
Photo by Sam Rutherford/Engadget

The m16 R2 has a single display option: a 16-inch 240Hz panel with a QHD+ resolution (2,560 x 1,600). It’s totally serviceable and for competitive gamers, that high refresh rate could be valuable during matches where potential advantage matters. But you don’t get any support for HDR, so colors don’t pop as much as they would on a system with an OLED screen. Furthermore, brightness is just OK at around 300 nits, which might not be a big deal if you prefer gaming at night or in darker environments. But if you plan on lugging this around to a place with big windows or a lot of sunlight, games and movies may look a bit subdued. That said, it’s not a deal breaker, I just wish this model had some other display options like the previous one.

While the m16 R2’s sleeker design is a major plus, the trade-off is less space for a beefy GPU. So unlike its predecessor, the biggest card that fits is an NVIDIA RTX 4070. This may come as a downer for performance enthusiasts, but Alienware said it made this change after seeing only a small fraction of buyers opt for RTX 4080 graphics on the old model. Even so, the R2 can still hold its own when playing AAA titles. In Cyberpunk 2077 at 1080p and ultra graphics, it hit 94 fps, barely behind what we saw from the ASUS ROG G16 (95 fps) with a more powerful 4080. And while the performance gap grew slightly when I turned ray tracing on, the m16 still pumped out a very playable framerate of 62 fps (versus 69 fps for the G16).

One of the biggest benefits of the m16 R2’s redesign is that it allowed Alienware to install a larger 90Wh battery versus the 84Wh pack in its predecessor. When you combine that with components and fans better tailored to the kind of performance this machine delivers, you get improved longevity. On our rundown test, the m16 R2 lasted 7 hours and 51 minutes, which is longer than both the Razer Blade 14 (6:46) and the ASUS ROG Zephyrus G14 (7:29) and just shy of what we got from a similarly specced XPS 16 (8:31). That said, it’s still not as good as the ASUS G16’s time of 9:17. Regardless, the ability to go longer between charges is never a bad thing. Meanwhile, for those who want to pack super light, one of the m16 R2’s USB-C ports in the back supports power input, though you won’t get the full 240 watts like you do with Alienware’s included brick.

As always, the m16 R2 has a light-up version of Alienware's iconic logo on its lid.
Photo by Sam Rutherford/Engadget

For 2024, it would have been so easy for Alienware to give the m16 a basic spec refresh and call it a day. But it didn’t. Instead, the company looked at its customers' preferences and gave it a revamp to match. So despite not having the same top-end performance as before, the R2 is still a very capable gaming laptop with a more compact chassis, improved battery life and a lower starting price of $1,500 with an RTX 4050. Sure, I wish its display was brighter and that there was another panel option, but getting 240Hz standard is pretty nice.

Really, the biggest argument against the m16 R2 is that for higher-specced systems like our $1,850 review unit with an RTX 4070, you can spend another $150 for an ASUS ROG G16 with the same GPU, a brighter and more colorful OLED display and an even lighter design that weighs a full pound less. But for people seeking a well-priced gaming machine that can do a bit of everything, there’s a lot of value in the m16 R2.

This article originally appeared on Engadget at https://www.engadget.com/alienware-m16-r2-review-when-less-power-makes-for-a-better-laptop-174027103.html?src=rss

Nintendo is done paying Elon Musk for X integration

Nintendo has apparently had enough of X’s (Twitter’s) API fees. The Mario maker said on Wednesday that starting on June 10, direct integration from the Switch’s image album to Elon Musk’s Nazi-curious platform will no longer work. With Nintendo’s departure, all three major console makers have pulled the plug on native screen-sharing to X.

X’s official gaming account posted a bizarre, downright Orwellian response that ignores its central role in the Mario maker’s exit. “Our partnership with Nintendo remains strong, and we are working together to ensure a smooth transition for all users,” @xGaming posted at the end of its nonchalantly misleading reply to Nintendo’s announcement. “We will continue collaborating with partners to bring new and exciting experiences to our global gaming community.”

Ironically, X’s built-in reader context feature filled in the omitted subtext. “This is in direct response to X changing their API,” the user-generated context says. “Specifically, X is charging companies upwards of $40,000 or more per month to access its API. Sony’s PlayStation and Microsoft’s Xbox already removed integration with X last year.”

Wired first reported last year that access to the cheapest Enterprise API plan for The Dumpster Fire Formerly Known As Twitter starts at $42,000 monthly. Higher tiers can allegedly cost $125,000 and $210,000 per month. Microsoft led the charge when it said the Xbox was abandoning Musk’s API plan in April 2023, while Sony held its nose and stuck it out until November.

The $42,000 (or more) monthly cost may not sound like much to these well-heeled mega-corporations, but apparently, even they have their limits. After all, quick screen-sharing to social channels is a marketing feature from a corporate perspective. If their accountants look at the analytics, weigh them against Musk’s fees and see it isn’t paying off, they’ll do what profit-driven entities do and reduce the overhead. But hey, at least X’s “partnership with Nintendo remains strong.”

Of course, you can still post Switch screenshots to Musk’s hellscape; it just has extra steps now. You can send Switch album images to your phone wirelessly or transfer them to your PC using a USB cable, and then post them manually. Nintendo says integrated Facebook sharing is still enabled but warns that it could be discontinued later.

This article originally appeared on Engadget at https://www.engadget.com/nintendo-is-done-paying-elon-musk-for-x-integration-165704399.html?src=rss

Watch the Google I/O 2024 Developer keynote live

Editor’s note (5/14/24): The main Google I/O keynote has ended, but the Google I/O Developer Keynote is now underway. Watch it below. 

It’s that time of year again. Google’s annual I/O keynote is upon us. This event is likely to be packed with updates and announcements. We’ll be covering all of the news as it happens and you can stream the full event below. The keynote starts at 1PM ET on May 14 and streams are available via YouTube and the company’s hub page.

In terms of what to expect, the rumor mill has been working overtime. There are multiple reports that the event will largely focus on the Android 15 mobile operating system, which seems like a given since I/O is primarily an event for developers and the beta version is already out in the wild.

So let’s talk about the Android 15 beta and what to expect from the full release. The beta includes an updated Privacy Sandbox feature, partial screen sharing to record a certain app or window instead of the whole screen and system-level app archiving to free up space. There’s also improved satellite connectivity, additional in-app camera controls and a new power efficiency mode.

Despite the beta already existing, it’s highly probable that Google will drop some surprise Android 15 announcements. The company has confirmed that satellite messaging is coming to Android, so maybe that’ll be part of this event. Rumors also suggest that Android 15 will boast a redesigned status bar and an easier way to monitor battery health.

An Android phone.
Sam Rutherford/Engadget

Android 15 won’t be the only thing Google discusses during the event. There’s a little acronym called AI you may have heard about and the company has gone all in. It’s a good bet that Google will spend a fair amount of time announcing updates for its Gemini AI, which could eventually replace Assistant entirely.

Back in December, it was reported that Google was working on an AI assistant called Pixie as an exclusive feature for Pixel devices. The branding is certainly on point. We could hear more about that, as it may debut in the Pixel 9 later this year. 

Google’s most popular products could also get AI-focused redesigns, including Search, Chrome, G Suite and Maps. We might get an update as to what the company plans on doing about third-party cookies and maybe it’ll throw some AI at that problem too.

What not to expect? Don’t get your hopes up for a Pixel 9 or refreshed Pixel Fold for this event, as I/O is more for software than hardware. We’ll likely get details on those releases in the fall. However, rules were made to be broken. Last year, we got a Pixel Fold announcement at I/O, so maybe the line between hardware and software is blurring. We’ll find out soon.

This article originally appeared on Engadget at https://www.engadget.com/how-to-watch-googles-io-2024-keynote-160010787.html?src=rss

Apple’s AirPods Max are $100 off and close to a record low

Most headphones don't last forever, especially wireless ones as the battery life will inevitably dwindle. If you're ready for an upgrade and you're willing to splash a little cash, Apple's AirPods Max are worth considering. Those headphones are currently on sale at Amazon. The price has dropped by $100 to $450, putting it at just $20 above the lowest price we've seen for the cans to date. The offer applies to all colorways.

The price was one of our major drawbacks when we reviewed the AirPods Max back in 2020 so the sale mitigates that a bit. We gave the headphones a score of 84, with the audio quality and aesthetics proving to be major plus points.

We felt that the AirPods Max had great balanced sound and capable active noise cancellation (ANC). With both spatial audio and ANC enabled, we had no trouble getting 20 hours of use out of the headphones on a single charge, just as Apple pledged.

Given that it's been a few years since the AirPods Max debuted and the fact Apple is in the midst of switching out the Lightning charging port for a USB-C one across all of its devices, a new version of the headphones may be on the way. That may result in Apple bringing the price of the original model down even further to clear out the stock. That said, if you don't want to wait, this is a solid deal on a good set of headphones, particularly if you're already entrenched in the Apple ecosystem.

Follow @EngadgetDeals on Twitter and subscribe to the Engadget Deals newsletter for the latest tech deals and buying advice.

This article originally appeared on Engadget at https://www.engadget.com/apples-airpods-max-are-100-off-and-close-to-a-record-low-143019278.html?src=rss