Google on Wednesday announced the release of a Chrome 105 update that resolves 11 vulnerabilities, including seven high-severity bugs reported by external researchers.
First on the list of externally reported security issues is an out-of-bounds write in Chrome’s Storage component. Next, there are three use-after-free flaws in the PDF component, complemented by a fourth use-after-free in Frames.
The remaining two vulnerabilities are a heap buffer overflow in Internals and an insufficient validation of untrusted input in DevTools, the company explains in an advisory. The internet giant has issued CVE identifiers CVE-2022-3195 through CVE-2022-3201 for these bugs.
Google says it has handed out $18,000 in bug bounty rewards for three of the flaws. The final amount will likely be higher, as the company has yet to determine the amount to be paid for three other bugs.
The latest browser update is now rolling out to Mac and Linux users as Chrome 105.0.5195.125. Windows users will receive it as Chrome 105.0.5195.125/126/127.
Just as with many of the latest Chrome releases, memory safety issues represented the most common type of vulnerabilities addressed in the popular browser.
Google has been long working on ways to squash these bugs, and last year announced the adoption of the Rust compiler, to prevent memory errors from happening. More recently, the company detailed MiraclePtr, new technology meant to prevent the exploitation of use-after-free flaws.
Related: Google Patches Sixth Chrome Zero-Day of 2022
Related: Chrome 105 Patches Critical, High-Severity Vulnerabilities
Related: Chrome Bug Allows Webpages to Replace Clipboard Contents

More from Ionut Arghire
- Ransomware Will Likely Target OT Systems in EU Transport Sector: ENISA
- Ransomware Gang Publishes Data Allegedly Stolen From Maritime Firm Royal Dirkzwager
- Zoom Paid Out $3.9 Million in Bug Bounties in 2022
- Malicious NuGet Packages Used to Target .NET Developers
- Google Pixel Vulnerability Allows Recovery of Cropped Screenshots
- Millions Stolen in Hack at Cryptocurrency ATM Manufacturer General Bytes
- NBA Notifying Individuals of Data Breach at Mailing Services Provider
- Adobe Acrobat Sign Abused to Distribute Malware
Latest News
- Burnout in Cybersecurity – Can it be Prevented?
- Spain Needs More Transparency Over Pegasus: EU Lawmakers
- Ransomware Will Likely Target OT Systems in EU Transport Sector: ENISA
- Virtual Event Today: Supply Chain & Third-Party Risk Summit
- Google Suspends Chinese Shopping App Amid Security Concerns
- Verosint Launches Account Fraud Detection and Prevention Platform
- Ransomware Gang Publishes Data Allegedly Stolen From Maritime Firm Royal Dirkzwager
- Zoom Paid Out $3.9 Million in Bug Bounties in 2022
