Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Vulnerabilities

Chrome 154 Patches 108 Vulnerabilities

The browser update resolves several critical-severity memory safety and memory corruption flaws.

Chrome security

Google on Tuesday announced the release of Chrome 154 to the stable channel with patches for 108 vulnerabilities, including 11 critical-severity bugs.

The critical security defects include buffer overflows (three in ANGLE and one in WebGL), out-of-bounds writes (two in GPU and one in WebGL), and use-after-free bugs in ServiceWorker, Fullscreen, WindowDialog, and AdFilter.

Nine of the critical issues were reported by external researchers. In total, 32 of the newly patched flaws were reported externally, while the rest were discovered by Google.

Google says it handed out $18,000 in bug bounty rewards to the reporting researchers, but the final amount could be much higher, as the company has yet to determine the amounts to be paid for most of the externally reported bugs.

Twenty-five of the remaining vulnerabilities are high-severity bugs, including a dozen use-after-free defects and multiple type confusion, uninitialized resource, and buffer overflow issues.

High-severity missing authorization, UI misinterpretation, incorrect authorization, improper output encoding, race condition, and out-of-bounds write flaws were also resolved.

Advertisement. Scroll to continue reading.

The remaining security holes are medium- and low-severity weaknesses related to authorization, input validation, UI misrepresentation, memory corruption, information leak, and memory safety.

Google makes no mention of any of these vulnerabilities being exploited in the wild, but users are advised to update their browsers as soon as possible.

The latest Chrome iteration is now rolling out as versions 154.0.8037.57/.58 for Windows and macOS, and as version 154.0.8037.57 for Linux.

Related: Chrome, Firefox Updates Patch 115 Vulnerabilities

Related: Arista Urges Immediate Patching of Exploited VCO Zero-Day

Related: Critical F5 BIG-IP Vulnerability Exploited as Zero-Day

Related: Check Point Patches Exploited Management Server Zero-Day

Written By

Ionut Arghire is an international correspondent for SecurityWeek.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join as speakers examine the various components of ASM strategy, the push to mandate continuous asset visibility and inventory tools, and the use of red-teaming, bug bounties and pen-tests in modern security programs.

Register

Explore what it takes to operationalize continuous authorization at scale, including the technical, organizational, and cultural changes required.

Register

People on the Move

Gwen Gann has become State Chief Information Security Officer for the State of Washington at WaTech.

Pietr Lindahal has been named Vice President and Chief Information Security Officer at Boston Scientific.

AI agent identity and enforcement company FIOR has appointed Gemma Ungoed-Thomas as Adviser.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.