Google has released a new security update for Chrome, version 150, aimed at fixing several critical memory safety vulnerabilities. The update addresses seven significant flaws, including critical and high-severity use-after-free vulnerabilities.
Key Vulnerabilities Addressed
The update resolves three critical use-after-free vulnerabilities that affect the CameraCapture, GPU, and Network components of Chrome. These issues were identified internally by Google’s security team.
In addition to these, three high-severity use-after-free flaws in the Cast, Ozone, and Aura components have also been patched. These vulnerabilities were similarly discovered by Google’s experts.
Additional Security Flaws
A separate out-of-bounds read and write flaw in the V8 JavaScript engine was found by OpenAI Codex Security. While Google has yet to announce the bug bounty for this discovery, the resolution of this issue is crucial for maintaining browser security.
Although there is no evidence of these vulnerabilities being exploited in the wild, Google strongly recommends users to update their browsers immediately to safeguard against potential threats.
Ongoing Efforts in Browser Security
For years, Google has been committed to enhancing Chrome’s security against memory safety exploits. This includes transitioning to more secure programming languages like Rust to mitigate such risks.
Since April, over 1,400 vulnerabilities have been patched in Chrome, with hundreds relating to memory safety, primarily identified through Google’s use of artificial intelligence.
The latest update is being rolled out as versions 150.0.7871.128/.129 for Windows and macOS, and as version 150.0.7871.128 for Linux. Users are encouraged to update their browsers promptly to benefit from these security enhancements.
Conclusion
Google’s proactive approach to addressing memory safety vulnerabilities in Chrome is part of its broader strategy to protect users from potential exploitation. As cyber threats continue to evolve, regular updates remain a critical component of maintaining robust browser security.
