Critical Vulnerabilities Patched With Chrome 151 Update

https://www.securityweek.com/wp-content/uploads/2023/04/Chrome-Zero-Day-exploits.jpg

Google on Thursday rolled out a fresh Chrome 151 update that patches 41 critical- and high-severity vulnerabilities.

Over two dozen security defects are memory safety bugs that could lead to data corruption, crashes, and arbitrary code execution.

The latest Chrome update resolves six critical-severity flaws, including five use-after-free issues in WebGL, Aura, Skia, and Views, and an out-of-bounds write in the ANGLE graphics engine.

Google credited external researchers for finding the two WebGL security defects, but has yet to determine the bug bounty rewards for them. The other four weaknesses were found by Google.

All the remaining 35 vulnerabilities resolved with the Chrome refresh are high-severity flaws. Google discovered 25 of them and credited external researchers for the other 10, but disclosed only two of the rewards it has handed out, both of $500.

Of the 35 issues, 24 are memory safety bugs, including use-after-free, buffer overflow, out-of-bounds write, and...

Copyright of this story solely belongs to securityweek.com. To see the full text click HERE

Read more