Security Experts:

Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Vulnerabilities

Google Chrome 48 Patches 37 Security Flaws

Google on Wednesday announced the availability of Chrome 48, a browser release that brings along 37 patches for various security vulnerabilities, including 8 that were reported by external researchers.

Google on Wednesday announced the availability of Chrome 48, a browser release that brings along 37 patches for various security vulnerabilities, including 8 that were reported by external researchers.

Two of the newly patched flaws, CVE-2016-1612 and CVE-2016-1613, were rated High risk and earned each researcher a $3,000 bounty. Google’s Krishna Govind explains in a blog post that one vulnerability was a Bad cast flaw in V8, reported by “cloudfuzzer”, while the other was a Use-after-free bug in PDFium reported by an anonymous researcher.

The rest of the six vulnerabilities reported by external researchers were all rated Medim risk. The first of them, CVE-2016-1614, was an Information leak in Blink, and earned researcher Christoph Diehl a $2,000 bounty.

The remaining five flaws were appraised $500 each. They included an Origin confusion issue in Omnibox (CVE-2016-1615), reported by Ron Masas; a URL Spoofing flaw (CVE-2016-1616) reported by Luan Herrera; History sniffing with HSTS and CSP (CVE-2016-1617), reported by jenuis; Weak random number generator in Blink (CVE-2016-1618), reported by Aaron Toponce; and Out-of-bounds read in PDFium (CVE-2016-1619), reported by Keve Nagy.

For the time being, however, Google hasn’t revealed the total value of additional rewards and their recipients, but said it would do so when all reports have gone through the reward panel. Details on these bugs haven’t been made public either, as Google awaits for the update to reach more users before revealing the information.

However, the company did say that Chrome 48 patches various other security flaws reported via internal audits, fuzzing and other initiatives: one rated Critical, 14 rated High, 10 Medium, and two Low. Google’s internal team also discovered multiple vulnerabilities in V8, which were patched “at the tip of the 4.8 branch.”

The new Chrome release, version 48.0.2564.82, is now available for download for Windows, Mac, and Linux users. In addition to security patches, the updated browser release also comes with a series of improvements, Google saud.

In December, Google patched 41 security bugs in its browser with the release of Chrome 47 and paid a total of more than $100,000 to researchers who contributed to making the release more secure. Released in mid-October, Chrome 46 patched a total of 24 security issues.

Written By

Click to comment

Expert Insights

Related Content

Mobile & Wireless

Technical details published for an Arm Mali GPU flaw leading to arbitrary kernel code execution and root on Pixel 6.

Mobile & Wireless

Apple rolled out iOS 16.3 and macOS Ventura 13.2 to cover serious security vulnerabilities.

Cloud Security

VMware vRealize Log Insight vulnerability allows an unauthenticated attacker to take full control of a target system.

Mobile & Wireless

Apple’s iOS 12.5.7 update patches CVE-2022-42856, an actively exploited vulnerability, in old iPhones and iPads.

Vulnerabilities

Security researchers have observed an uptick in attacks targeting CVE-2021-35394, an RCE vulnerability in Realtek Jungle SDK.

Vulnerabilities

Google has awarded more than $25,000 to the researchers who reported the vulnerabilities patched with the release of the latest Chrome update.

Mobile & Wireless

Two vulnerabilities in Samsung’s Galaxy Store that could be exploited to install applications or execute JavaScript code by launching a web page.

Vulnerabilities

Several vulnerabilities have been patched in OpenText’s enterprise content management (ECM) product.