Google on Tuesday announced the release of Chrome 154 to the stable channel with patches for 108 vulnerabilities, including 11 critical-severity bugs.
The critical security defects include buffer overflows (three in ANGLE and one in WebGL), out-of-bounds writes (two in GPU and one in WebGL), and use-after-free bugs in ServiceWorker, Fullscreen, WindowDialog, and AdFilter.
Nine of the critical issues were reported by external researchers. In total, 32 of the newly patched flaws were reported externally, while the rest were discovered by Google.
Google says it handed out $18,000 in bug bounty rewards to the reporting researchers, but the final amount could be much higher, as the company has yet to determine the amounts to be paid for most of the externally reported bugs.
Twenty-five of the remaining vulnerabilities are high-severity bugs, including a dozen use-after-free defects and multiple type confusion, uninitialized resource, and buffer overflow issues.
High-severity missing authorization, UI misinterpretation, incorrect authorization, improper output encoding, race condition, and out-of-bounds write flaws were also resolved.
The remaining security holes are medium- and low-severity weaknesses related to authorization, input validation, UI misrepresentation, memory corruption, information leak, and memory safety.
Google makes no mention of any of these vulnerabilities being exploited in the wild, but users are advised to update their browsers as soon as possible.
The latest Chrome iteration is now rolling out as versions 154.0.8037.57/.58 for Windows and macOS, and as version 154.0.8037.57 for Linux.
Related: Chrome, Firefox Updates Patch 115 Vulnerabilities
Related: Arista Urges Immediate Patching of Exploited VCO Zero-Day
Related: Critical F5 BIG-IP Vulnerability Exploited as Zero-Day
Related: Check Point Patches Exploited Management Server Zero-Day
