Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Vulnerabilities

Chrome 128 Update Resolves High-Severity Vulnerabilities

Google has released a Chrome 128 security update to resolve high-severity memory safety vulnerabilities.

Chrome security

Google on Tuesday announced a new Chrome 128 update that addresses five vulnerabilities, including four reported by external researchers.

All four externally reported flaws are high-severity memory safety issues that were reported in late August, after Chrome 128 was released in the stable channel.

The first of them, tracked as CVE-2024-8636, is a heap buffer overflow bug in Skia, the open source 2D graphics library that serves as the graphics engine in the browser.

Next in line is CVE-2024-8637, a use-after-free security defect in Media Router. Due to the incorrect use of memory allocation, use-after-free vulnerabilities could lead to code execution, data corruption, or denial-of-service. In Chrome they could be combined with other flaws for a sandbox escape.

The third bug reported by external researchers is CVE-2024-8638, a type confusion in the V8 JavaScript engine. Such security defects typically lead to unexpected application behavior, crashes, and remote code execution.

The fourth externally reported vulnerability addressed with the latest Chrome update is CVE-2024-8639, a use-after-free flaw in Autofill.

Advertisement. Scroll to continue reading.

Google says it handed out $15,000 and $11,000 in bug bounty rewards for the first two security defects, but has yet to determine the amounts to be paid for the last two.

The new browser update is now rolling out as Chrome versions 128.0.6613.137/.138 for Windows and macOS, and as version 128.0.6613.137 for Linux.

Google makes no mention of any of these security defects being exploited in the wild. However, users should update their browsers as soon as possible.

This is the third Chrome 128 update to be released over the course of as many weeks. The previous two updates resolved eight vulnerabilities, including six reported by external researchers.

Related: Google Warns of Exploited Chrome Vulnerability

Related: Chrome, Firefox Updates Patch Serious Vulnerabilities

Related: Emsisoft Tells Users to Update Products, Reboot Systems Due to Certificate Mishap

Related: Chrome 114 Update Patches High-Severity Vulnerabilities

Written By

Ionut Arghire is an international correspondent for SecurityWeek.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Today’s attackers are no longer breaking in — they’re logging in. Join this live webinar as we break down the modern identity attack chain and examine how recent breaches exploited weaknesses in authentication, identity verification, and access management processes.

Register

AI has accelerated both sides of the fight. Adversaries are weaponizing vulnerabilities faster, while defenders are racing to ship detections and configurations. Join this live webinar as we explore how to prove your controls actually hold against new threats, map your security maturity, and unite breach simulation with automated pentesting into a single, coordinated program.

Register

People on the Move

SolarWinds has appointed Justin Henkel as Chief Information Security Officer.

J. Paul Haynes has joined Cinchy as Chief Executive Officer.

Hatem Naguib has become Chief Executive Officer at Sysdig.

More People On The Move

Expert Insights

Four decades of incident response experience suggest that exploits are often the symptom, not the root cause, of today’s cybersecurity failures.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.