Chrome 128 Update Resolves High-Severity Vulnerabilities

1 month ago 12
News Banner

Looking for an Interim or Fractional CTO to support your business?

Read more

Google on Tuesday announced a new Chrome 128 update that addresses five vulnerabilities, including four reported by external researchers.

All four externally reported flaws are high-severity memory safety issues that were reported in late August, after Chrome 128 was released in the stable channel.

The first of them, tracked as CVE-2024-8636, is a heap buffer overflow bug in Skia, the open source 2D graphics library that serves as the graphics engine in the browser.

Next in line is CVE-2024-8637, a use-after-free security defect in Media Router. Due to the incorrect use of memory allocation, use-after-free vulnerabilities could lead to code execution, data corruption, or denial-of-service. In Chrome they could be combined with other flaws for a sandbox escape.

The third bug reported by external researchers is CVE-2024-8638, a type confusion in the V8 JavaScript engine. Such security defects typically lead to unexpected application behavior, crashes, and remote code execution.

The fourth externally reported vulnerability addressed with the latest Chrome update is CVE-2024-8639, a use-after-free flaw in Autofill.

Google says it handed out $15,000 and $11,000 in bug bounty rewards for the first two security defects, but has yet to determine the amounts to be paid for the last two.

The new browser update is now rolling out as Chrome versions 128.0.6613.137/.138 for Windows and macOS, and as version 128.0.6613.137 for Linux.

Advertisement. Scroll to continue reading.

Google makes no mention of any of these security defects being exploited in the wild. However, users should update their browsers as soon as possible.

This is the third Chrome 128 update to be released over the course of as many weeks. The previous two updates resolved eight vulnerabilities, including six reported by external researchers.

Related: Google Warns of Exploited Chrome Vulnerability

Related: Chrome, Firefox Updates Patch Serious Vulnerabilities

Related: Emsisoft Tells Users to Update Products, Reboot Systems Due to Certificate Mishap

Related: Chrome 114 Update Patches High-Severity Vulnerabilities

Read Entire Article