Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Vulnerabilities

Critical Vulnerabilities Patched With Chrome 151 Update

The browser refresh eliminates over two dozen memory safety bugs, including critical use-after-free flaws.

Chrome security

Google on Thursday rolled out a fresh Chrome 151 update that patches 41 critical- and high-severity vulnerabilities.

Over two dozen security defects are memory safety bugs that could lead to data corruption, crashes, and arbitrary code execution.

The latest Chrome update resolves six critical-severity flaws, including five use-after-free issues in WebGL, Aura, Skia, and Views, and an out-of-bounds write in the ANGLE graphics engine.

Google credited external researchers for finding the two WebGL security defects, but has yet to determine the bug bounty rewards for them. The other four weaknesses were found by Google.

All the remaining 35 vulnerabilities resolved with the Chrome refresh are high-severity flaws. Google discovered 25 of them and credited external researchers for the other 10, but disclosed only two of the rewards it has handed out, both of $500.

Of the 35 issues, 24 are memory safety bugs, including use-after-free, buffer overflow, out-of-bounds write, and uninitialized use defects.

Advertisement. Scroll to continue reading.

The remaining flaws include insufficient validations of untrusted input, inappropriate implementations, race conditions, and integer overflows.

While the new Chrome update does not include as many fixes as most of the recent browser refreshes, it does show that Google’s use of AI drives a faster patching pace.

The latest Chrome iteration is now rolling out as versions 151.0.7922.108/.109 for Windows and macOS, and as version 151.0.7922.108 for Linux.

While Google makes no mention of any of these vulnerabilities being exploited in the wild, users are advised to update their browsers as soon as possible.

Related: Chrome 151 Patches 370 Vulnerabilities

Related: Critical Paperclip Flaw Allowed Admin Access, Code Execution

Related: Cisco Patches Critical SD-WAN, IOS XE, FMC Vulnerabilities

Related: Hackers Start Exploiting Recent JetBrains TeamCity Vulnerability

Written By

Ionut Arghire is an international correspondent for SecurityWeek.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join as speakers examine the various components of ASM strategy, the push to mandate continuous asset visibility and inventory tools, and the use of red-teaming, bug bounties and pen-tests in modern security programs.

Register

Explore what it takes to operationalize continuous authorization at scale, including the technical, organizational, and cultural changes required.

Register

People on the Move

Veritas Capital has appointed Joel Fulton as Chief Information Security Officer.

incident.io has appointed Carlos Gonzalez-Cadenas as Chief Operating Officer.

Ruben D. Chacon has joined ADM as Vice President and Global CISO.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.