Google releases update to fix six critical vulnerabilities in Chrome

Google has released a critical security update for its Chrome browser, addressing six vulnerabilities, four of which were identified by third-party developers. Among the most significant issues are type confusion (CVE-2024-5158) and use-after-free (CVE-2024-5157), which could lead to data leakage and the insertion of malicious software.

The use-after-free flaw, related to memory corruption, potentially allows hackers to install malicious applications. The second serious vulnerability, type confusion, has repeatedly been found in Chromium-based browsers and the Javascript V8 engine. Cyber attackers can exploit the type confusion bug through a specialized malicious HTML page, as previously reported by cybersecurity firm SocRadar.

The buffer overflow error, CVE-2024-5159, was found in Chrome’s Angle graphic engine. Another vulnerability, CVE-2024-5160, was discovered in Dawn, Google’s open standard for the WebGPU API.

Details about these four vulnerabilities emerged within the past five weeks. Fixes are being dispatched to Windows and Mac users via Chrome versions 125.0.6422.76/.77, and to Linux users via build 125.0.6422.76. According to Google, these updates will be available for download in the coming days or weeks. As is the norm, Google has awarded monetary prizes amounting to 26,000 dollars to the three developers who discovered these and other security flaws.

It is worth noting that earlier this month, Google had already released an urgent Chrome update to rectify a critical vulnerability, CVE-2024-4671. This was also a use-after-free error, which could be used to install malicious software on a user’s computer.

This post was last modified on 05/22/2024

Matthew Harmon: Hey folks, I'm Matt Harmon, your storyteller in the dynamic realm where technology and gaming collide. As an author for tech and gaming news on Dave's iPAQ, I'm on a mission to unravel the tales that shape the digital landscapes we live, work, and play in. From the pixelated nostalgia of retro consoles to the immersive worlds of virtual reality, gaming is more than a passion – it's a way of life. I delve into the latest releases, gaming industry trends, and the ever-evolving technology that elevates our gaming experiences. In the fast-paced world of technology, I'm your guide through the digital labyrinth. Whether it's the latest gadgets, software updates, or breakthrough innovations, I'm here to break down the jargon and deliver tech news in a way that's accessible to all. Working on Dave's iPAQ isn't just a job; it's an opportunity to connect with a community that shares the excitement for the convergence of technology and gaming. I engage in discussions, share insights, and explore the interplay between the virtual and the real.