Google Releases Chrome Update to Fix 108 Vulnerabilities
Share
Google has released Chrome 154 to the stable channel, addressing 108 vulnerabilities, including 11 critical-severity defects. The update focuses on resolving several high-impact memory safety and memory corruption flaws.
The critical vulnerabilities include three buffer overflows in ANGLE, one in WebGL, and two out-of-bounds writes in the GPU. Additionally, the patch resolves use-after-free bugs affecting ServiceWorker, Fullscreen, WindowDialog, and AdFilter.
Of the 108 newly patched flaws, 32 were identified by external researchers. Google has confirmed it has distributed $18,000 in bug bounty rewards to these researchers, though the final total is expected to increase as the company processes the remaining externally reported bugs.
High-Severity and Other Flaws Resolved
Beyond the critical issues, the update addresses 25 high-severity vulnerabilities. These include a dozen use-after-free defects, as well as multiple instances of type confusion, uninitialized resources, and buffer overflows. The release also resolves high-severity flaws related to missing authorisation, incorrect authorisation, race conditions, and improper output encoding.
The remaining vulnerabilities are classified as medium- or low-severity and involve issues such as input validation, UI misrepresentation, information leaks, and memory safety.
Google has not reported any evidence that these vulnerabilities are being actively exploited in the wild. However, due to the number of critical flaws, users are advised to update their browsers immediately.
The latest version of Chrome is now available as 154.0.8037.57/.58 for Windows and macOS, and version 154.0.8037.57 for Linux.




Leave a Reply