Vulnerabilities

Chrome 121 Patches 17 Vulnerabilities

Google releases Chrome 121 to the stable channel with 17 security fixes, including 11 reported by external researchers.

Google releases Chrome 121 to the stable channel with 17 security fixes, including 11 reported by external researchers.

Google on Tuesday announced the promotion of Chrome 121 to the stable channel with patches for 17 vulnerabilities, including 11 reported by external researchers.

Of the externally reported security defects, three have a severity rating of ‘high’. Google says it handed out over $30,000 in bug bounty rewards to the reporting researchers.

The first high-severity bug that Chrome 121 addresses is a use-after-free issue in WebAudio. Tracked as CVE-2024-0807, the flaw earned the reporting researcher a $11,000 bug bounty.

Next in line is CVE-2024-0812, described as an inappropriate implementation in Accessibility. Google handed out a $9,000 reward for this security hole.

The third high-severity vulnerability is CVE-2024-0808, an integer underflow in WebUI, for which a $6,000 bug bounty was handed out, Google says in its advisory.

Chrome 121 also resolves six medium-severity issues, including two insufficient policy enforcement bugs, two use-after-free flaws, an incorrect security UI defect, and an inappropriate implementation.

Advertisement. Scroll to continue reading.

Two other low-severity inappropriate implementation vulnerabilities were also patched.

Google, which is keeping technical details on the resolved bugs restricted for now, made no mention of any of these vulnerabilities being exploited in the wild.

The latest Chrome iteration is now rolling out as version 121.0.6167.85 for macOS and Linux, and as versions 121.0.6167.85/.86 for Windows.

The update comes roughly one week after Google rushed out patches for the first Chrome zero-day of 2024, an out-of-bounds memory access issue in the V8 JavaScript engine that could be exploited by remote attackers via crafted HTML pages.

Last year, Google addressed eight exploited Chrome zero-days, including several vulnerabilities believed to have been exploited by commercial spyware vendors.

Related: Google Patches Six Vulnerabilities With First Chrome Update of 2024

Related: Chrome 120 Patches 10 Vulnerabilities

Related: Chrome 119 Patches 15 Vulnerabilities

Related: Chrome 118 Patches 20 Vulnerabilities

Related Content

Vulnerabilities

The fresh security update resolves six critical and high-severity use-after-free vulnerabilities.

Vulnerabilities

Public exploit code targeting the Firefox flaws exists, but no in-the-wild exploitation has been observed.

Vulnerabilities

The security refresh resolves 13 use-after-free bugs, including two critical-severity flaws found by Google.

Vulnerabilities

Fifteen of the newly patched flaws have been rated ‘critical’ and 67 have been rated ‘high severity’.

Vulnerabilities

More than half of the bugs are use-after-free defects, which can potentially lead to remote code execution.

Vulnerabilities

The browser updates address multiple memory safety bugs that could potentially lead to remote code execution.

Vulnerabilities

The browser refresh resolved critical and high-severity security defects, including a dozen use-after-free bugs.

Vulnerabilities

The vulnerability is tracked as CVE-2026-11645 and it was reported in late April by an anonymous researcher.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version