Security Experts:

Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Vulnerabilities

High-Severity Memory Safety Bugs Patched With Latest Chrome 108 Update

Google this week announced a Chrome update that resolves eight vulnerabilities in the popular browser, including five reported by external researchers.

Google this week announced a Chrome update that resolves eight vulnerabilities in the popular browser, including five reported by external researchers.

All five security defects are use-after-free flaws, a type of memory safety bug that has been prevalent in Chrome over the past years, and which Google has long-battled to eliminate.

According to Google’s advisory, four of these issues are high-severity bugs, impacting components such as Blink Media, Mojo IPC, Blink Frames, and Aura.

The vulnerabilities have been issued CVE identifiers CVE-2022-4436 to CVE-2022-4439 and are accompanied by CVE-2022-4440, a medium-severity use-after-free.

Google says it has paid $17,500 in bug bounties to the reporting researchers, but the final amount might be higher, as only four out of five rewards have been disclosed.

The latest Chrome browser release is currently rolling out to Mac and Linux users as version 108.0.5359.124, and to Windows users as version 108.0.5359.124/.125.

Google makes no mention of any of these vulnerabilities being exploited in malicious attacks. To date, there have been nine documented Chrome zero-day flaws in 2022.

Related to the incorrect use of dynamic memory while a program is running, use-after-free issues exist because, after freeing a memory location, an application might not clear the pointer to that location.

An attacker in a position to exploit a use-after-free vulnerability may be able to crash the application, corrupt data, or execute arbitrary code on the machine. In Chrome, use-after-free flaws may be used to escape the browser sandbox, which requires the exploitation of additional security defects.

Over the past couple of years, Google announced several efforts to eliminate memory safety bugs in both Android and Chrome, and recently announced improved protections against the exploitation of such vulnerabilities.

Related: Chrome 108 Patches High-Severity Memory Safety Bugs

Related: Google Patches Eighth Chrome Zero-Day of 2022

Related: NSA Publishes Guidance on Mitigating Software Memory Safety Issues

Written By

Ionut Arghire is an international correspondent for SecurityWeek.

Click to comment

Expert Insights

Related Content

Mobile & Wireless

Technical details published for an Arm Mali GPU flaw leading to arbitrary kernel code execution and root on Pixel 6.

Mobile & Wireless

Apple rolled out iOS 16.3 and macOS Ventura 13.2 to cover serious security vulnerabilities.

Cloud Security

VMware vRealize Log Insight vulnerability allows an unauthenticated attacker to take full control of a target system.

Mobile & Wireless

Apple’s iOS 12.5.7 update patches CVE-2022-42856, an actively exploited vulnerability, in old iPhones and iPads.

Mobile & Wireless

Two vulnerabilities in Samsung’s Galaxy Store that could be exploited to install applications or execute JavaScript code by launching a web page.

Vulnerabilities

Security researchers have observed an uptick in attacks targeting CVE-2021-35394, an RCE vulnerability in Realtek Jungle SDK.

Vulnerabilities

Several vulnerabilities have been patched in OpenText’s enterprise content management (ECM) product.

Application Security

Drupal released updates that resolve four vulnerabilities in Drupal core and three plugins.