Chrome 149 Update Resolves 18 Severe Vulnerabilities

https://www.securityweek.com/wp-content/uploads/2024/06/Chrome.jpeg

Google on Wednesday rolled out a new Chrome 149 update that resolves 18 vulnerabilities, including four critical and 14 high-severity security defects.

More than half of the addressed issues, including three critical and seven high-severity, are use-after-free flaws, a type of memory corruption bug that could lead to remote code execution (RCE).

In Chrome, use-after-free vulnerabilities can be combined with security holes in the underlying operating system or in a privileged browser process to escape the sandbox.

The remaining eight issues patched in this update are out-of-bounds read, inappropriate implementation, uninitialized use, and insufficient validation of untrusted input bugs.

Per Google’s advisory, the most severe of the flaws was reported by an anonymous researcher. The company has yet to disclose the bug bounty amount to be rewarded for the report.

The remaining 17 security defects were discovered by Google, a trend that has been ongoing for the past couple...

Copyright of this story solely belongs to securityweek.com. To see the full text click HERE

Read more