Chrome and Firefox Updated to Patch Critical, High-Severity Vulnerabilities
Fresh Chrome and Firefox updates are now rolling out with fixes for over 70 vulnerabilities, including critical and high-severity memory safety bugs that could potentially lead to remote code execution (RCE).
Chrome has been updated to versions 149.0.7827.155/.156 for Windows and macOS and version 149.0.7827.155 for Linux to resolve 33 security defects, 32 of which were found by Google.
Of the seven critical-severity flaws mentioned in Google’s advisory, six are use-after-free issues, a type of memory safety bug that could be exploited for RCE.
In Chrome, these weaknesses could lead to sandbox escape if combined with the exploitation of vulnerabilities in the operating system or in a privileged browser process.
The fresh Chrome release also patches 26 high-severity bugs, including eight use-after-free flaws, along with insufficient data validation, inappropriate implementation, out-of-bounds read, incorrect security UI, heap buffer overflow, and uninitialized use issues.
Google makes no mention of any of...
Copyright of this story solely belongs to securityweek.com. To see the full text click HERE