Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Vulnerabilities

Critical Vulnerabilities Patched With Chrome 151 Update

The browser refresh eliminates over two dozen memory safety bugs, including critical use-after-free flaws.

Chrome security

Google on Thursday rolled out a fresh Chrome 151 update that patches 41 critical- and high-severity vulnerabilities.

Over two dozen security defects are memory safety bugs that could lead to data corruption, crashes, and arbitrary code execution.

The latest Chrome update resolves six critical-severity flaws, including five use-after-free issues in WebGL, Aura, Skia, and Views, and an out-of-bounds write in the ANGLE graphics engine.

Google credited external researchers for finding the two WebGL security defects, but has yet to determine the bug bounty rewards for them. The other four weaknesses were found by Google.

All the remaining 35 vulnerabilities resolved with the Chrome refresh are high-severity flaws. Google discovered 25 of them and credited external researchers for the other 10, but disclosed only two of the rewards it has handed out, both of $500.

Of the 35 issues, 24 are memory safety bugs, including use-after-free, buffer overflow, out-of-bounds write, and uninitialized use defects.

Advertisement. Scroll to continue reading.

The remaining flaws include insufficient validations of untrusted input, inappropriate implementations, race conditions, and integer overflows.

While the new Chrome update does not include as many fixes as most of the recent browser refreshes, it does show that Google’s use of AI drives a faster patching pace.

The latest Chrome iteration is now rolling out as versions 151.0.7922.108/.109 for Windows and macOS, and as version 151.0.7922.108 for Linux.

While Google makes no mention of any of these vulnerabilities being exploited in the wild, users are advised to update their browsers as soon as possible.

Related: Chrome 151 Patches 370 Vulnerabilities

Related: Critical Paperclip Flaw Allowed Admin Access, Code Execution

Related: Cisco Patches Critical SD-WAN, IOS XE, FMC Vulnerabilities

Related: Hackers Start Exploiting Recent JetBrains TeamCity Vulnerability

Written By

Ionut Arghire is an international correspondent for SecurityWeek.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join this live webinar as we explore if detection-first security operations can keep pace with AI, or if it’s time to rethink prevention as the strongest default.

Register

CodeSecCon bridges the gap between dev and security. Discover best practices for secure coding, innovative risk-reduction tools, and safe AI integration to cultivate a true DevSecOps culture. Safely secure your apps!

Register

People on the Move

1Kosmos has named Frank Cohen Chief Revenue Officer.

ServiceNow has appointed Simon Mouyal as Chief Marketing Officer.

James Wilkinson has been named Chief Information Security Officer for the City of Dallas.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.