Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Vulnerabilities

Chrome 121 Patches 17 Vulnerabilities

Google releases Chrome 121 to the stable channel with 17 security fixes, including 11 reported by external researchers.

Google on Tuesday announced the promotion of Chrome 121 to the stable channel with patches for 17 vulnerabilities, including 11 reported by external researchers.

Of the externally reported security defects, three have a severity rating of ‘high’. Google says it handed out over $30,000 in bug bounty rewards to the reporting researchers.

The first high-severity bug that Chrome 121 addresses is a use-after-free issue in WebAudio. Tracked as CVE-2024-0807, the flaw earned the reporting researcher a $11,000 bug bounty.

Next in line is CVE-2024-0812, described as an inappropriate implementation in Accessibility. Google handed out a $9,000 reward for this security hole.

The third high-severity vulnerability is CVE-2024-0808, an integer underflow in WebUI, for which a $6,000 bug bounty was handed out, Google says in its advisory.

Chrome 121 also resolves six medium-severity issues, including two insufficient policy enforcement bugs, two use-after-free flaws, an incorrect security UI defect, and an inappropriate implementation.

Two other low-severity inappropriate implementation vulnerabilities were also patched.

Google, which is keeping technical details on the resolved bugs restricted for now, made no mention of any of these vulnerabilities being exploited in the wild.

Advertisement. Scroll to continue reading.

The latest Chrome iteration is now rolling out as version 121.0.6167.85 for macOS and Linux, and as versions 121.0.6167.85/.86 for Windows.

The update comes roughly one week after Google rushed out patches for the first Chrome zero-day of 2024, an out-of-bounds memory access issue in the V8 JavaScript engine that could be exploited by remote attackers via crafted HTML pages.

Last year, Google addressed eight exploited Chrome zero-days, including several vulnerabilities believed to have been exploited by commercial spyware vendors.

Related: Google Patches Six Vulnerabilities With First Chrome Update of 2024

Related: Chrome 120 Patches 10 Vulnerabilities

Related: Chrome 119 Patches 15 Vulnerabilities

Related: Chrome 118 Patches 20 Vulnerabilities

Written By

Ionut Arghire is an international correspondent for SecurityWeek.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join the session as we discuss the challenges and best practices for cybersecurity leaders managing cloud identities.

Register

SecurityWeek’s Ransomware Resilience and Recovery Summit helps businesses to plan, prepare, and recover from a ransomware incident.

Register

People on the Move

Mike Dube has joined cloud security company Aqua Security as CRO.

Cody Barrow has been appointed as CEO of threat intelligence company EclecticIQ.

Shay Mowlem has been named CMO of runtime and application security company Contrast Security.

More People On The Move

Expert Insights

Related Content

Vulnerabilities

Less than a week after announcing that it would suspended service indefinitely due to a conflict with an (at the time) unnamed security researcher...

Data Breaches

OpenAI has confirmed a ChatGPT data breach on the same day a security firm reported seeing the use of a component affected by an...

IoT Security

A group of seven security researchers have discovered numerous vulnerabilities in vehicles from 16 car makers, including bugs that allowed them to control car...

Vulnerabilities

A researcher at IOActive discovered that home security systems from SimpliSafe are plagued by a vulnerability that allows tech savvy burglars to remotely disable...

Risk Management

The supply chain threat is directly linked to attack surface management, but the supply chain must be known and understood before it can be...

Cybercrime

Patch Tuesday: Microsoft calls attention to a series of zero-day remote code execution attacks hitting its Office productivity suite.

Vulnerabilities

Patch Tuesday: Microsoft warns vulnerability (CVE-2023-23397) could lead to exploitation before an email is viewed in the Preview Pane.

IoT Security

A vulnerability affecting Dahua cameras and video recorders can be exploited by threat actors to modify a device’s system time.