Malware & Threats

Google Pays $55,000 for High-Severity Chrome Browser Bug

Google pushes out major Chrome browser updates to fix multiple serious security defects.

Chrome security

Google has pushed a major Chrome browser update to patch three vulnerabilities, including two high-severity memory safety bugs reported by external researchers.

The first of the externally reported issues, tracked as CVE-2024-12381, is a type confusion flaw in the V8 JavaScript engine that earned the reporting researcher a $55,000 bug bounty reward.

As customary, Google is keeping the technical details on this vulnerability restricted until patches have been rolled out for most users. Based on Google’s updated vulnerability rewards, it is highly likely that the security defect could be exploited to achieve remote code execution (RCE).

Prevalent in programming languages that lack memory safety mechanisms, such as C and C++, type confusion vulnerabilities occur when a resource with an incompatible type is accessed, which leads to logical errors.

Type confusion bugs in Chrome’s V8 JavaScript engine could allow threat actors to execute malicious code and potentially access sensitive information or compromise the user’s system.

Last week, Google patched another type confusion vulnerability in V8 reported by an external researcher, and announced that it handed out an $8,000 bug bounty reward. The issue is tracked as CVE-2024-12053.

Advertisement. Scroll to continue reading.

The latest Chrome 131 update also resolves CVE-2024-12382, a use-after-free security defect in Chrome’s Translate component. Google has yet to disclose the bug bounty amount to be paid for this bug.

In addition to releasing two Chrome 131 security updates, Google also updated the browser’s Extended Stable channel twice over the past week. The latest version is now rolling out as version 130.0.6723.160 for Windows and macOS.

The latest Chrome iteration is being distributed as versions 131.0.6778.139/.140 for Windows and macOS, and as version 131.0.6778.139 for Linux.

Google makes no mention of any of these vulnerabilities being exploited in the wild, but threat actors have been observed targeting flaws in Chrome’s V8 engine.

Related: Glove Stealer Malware Bypasses Chrome’s App-Bound Encryption

Related: High-Severity Vulnerabilities Patched in Zoom, Chrome

Related: Google Patches Critical Chrome Vulnerability Reported by Apple

Related: North Korean Hackers Exploited Chrome Zero-Day for Cryptocurrency Theft

Related Content

Cyberwarfare

The vulnerability, tracked as CVE-2025-2783, was chained with a second exploit for remote code execution in attacks targeting organizations in Russia.

Funding/M&A

Seraphic Security banks $29 million investment as VCs remain bullish on startups with security-themed browsers for corporate defenders.

Mobile & Wireless

Memory safety bugs in Android have decreased significantly as old code matures and new code uses memory-safe languages.

Vulnerabilities

Redmond's threat intel team said exploitation of CVE-2024-7971 can be attributed to a North Korean APT targeting the cryptocurrency sector for financial gain.

Malware & Threats

Google TAG publishes evidence showing identical or striking similarities between exploits used by Russia's APT29 and commercial spyware vendors.

Cloud Security

Despite competitive pressures from industry behemoths like Microsoft and Google, investors are still betting big on startups in the specialized enterprise browser space.

Malware & Threats

Google ships a security-themed Chrome browser refresh to fix flaws exploited at the CanSecWest Pwn2Own hacking contest.

Cloud Security

Attackers could take over a Kubernetes cluster if access privileges are granted to all authenticated users in Google Kubernetes Engine.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version