Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Vulnerabilities

Google Pays Out $41,000 for Three Serious Chrome Vulnerabilities

Google releases a Chrome 123 update to resolve three high-severity memory safety vulnerabilities.

Chrome security updates

Google on Wednesday released a new Chrome 123 security update that addresses three high-severity memory safety bugs reported by external researchers.

The first vulnerability, tracked as CVE-2024-3157, is described as an out-of-bounds write issue in Compositing. The internet giant handed out a $21,000 bug bounty reward for this flaw.

According to a NIST advisory, a remote attacker who has compromised the GPU process could exploit this vulnerability to perform a sandbox escape via specific UI gestures.

Tracked as CVE-2024-3516, the second security defect is a heap buffer overflow bug in the ANGLE rendering engine that could allow a remote attacker to exploit heap corruption via malicious web pages.

The third issue, tracked as CVE-2024-3515, is a use-after-free bug in Dawn, also leading to the exploitation of heap corruption via crafted web pages.

Google notes in its advisory that it paid out bug bounty rewards of $10,000 for each of the last two security holes.

The latest Chrome update is now rolling out as version 123.0.6312.122 for Linux, versions 123.0.6312.122/.123 for Windows, and versions 123.0.6312.122/.123/.124 for macOS.

The internet giant makes no mention of any of these vulnerabilities being exploited in malicious attacks.

Advertisement. Scroll to continue reading.

However, memory safety bugs in Chrome have been a major issue, as all the browser zero-days exploited in the wild between 2021 and 2023 started with a memory corruption bug leading to remote code execution.

Google has been battling memory safety bugs in Chrome for a while, with the introduction of runtime checks and the transition to the Rust programming language, which is considered memory safe, and has made the exploitation of use-after-free flaws more difficult.

Last week, the company announced the addition of a sandbox for V8, to prevent the exploitation of memory safety bugs in the browser’s JavaScript engine.

Related: Chrome to Fight Cookie Theft With Device Bound Session Credentials

Related: Google Patches Chrome Flaw That Earned Hackers $42,500 at Pwn2Own

Related: Chrome Update Patches Zero-Day Vulnerabilities Exploited at Pwn2Own

Written By

Ionut Arghire is an international correspondent for SecurityWeek.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join the session as we discuss the challenges and best practices for cybersecurity leaders managing cloud identities.

Register

SecurityWeek’s Ransomware Resilience and Recovery Summit helps businesses to plan, prepare, and recover from a ransomware incident.

Register

People on the Move

Mike Dube has joined cloud security company Aqua Security as CRO.

Cody Barrow has been appointed as CEO of threat intelligence company EclecticIQ.

Shay Mowlem has been named CMO of runtime and application security company Contrast Security.

More People On The Move

Expert Insights

Related Content

Vulnerabilities

Less than a week after announcing that it would suspended service indefinitely due to a conflict with an (at the time) unnamed security researcher...

Data Breaches

OpenAI has confirmed a ChatGPT data breach on the same day a security firm reported seeing the use of a component affected by an...

IoT Security

A group of seven security researchers have discovered numerous vulnerabilities in vehicles from 16 car makers, including bugs that allowed them to control car...

Vulnerabilities

A researcher at IOActive discovered that home security systems from SimpliSafe are plagued by a vulnerability that allows tech savvy burglars to remotely disable...

Risk Management

The supply chain threat is directly linked to attack surface management, but the supply chain must be known and understood before it can be...

Cybercrime

Patch Tuesday: Microsoft calls attention to a series of zero-day remote code execution attacks hitting its Office productivity suite.

Vulnerabilities

Patch Tuesday: Microsoft warns vulnerability (CVE-2023-23397) could lead to exploitation before an email is viewed in the Preview Pane.

IoT Security

A vulnerability affecting Dahua cameras and video recorders can be exploited by threat actors to modify a device’s system time.