Chrome 154 Patches 108 Vulnerabilities
Google released Chrome 154, addressing 108 vulnerabilities, including 11 critical bugs. The update focuses on fixing a range of issues like buffer overflows and use-after-free errors, and Google rewarded researchers for their findings. Users are strongly advised to update immediately to mitigate potential risks.
Google released Chrome 154 on Tuesday, incorporating patches for 108 security vulnerabilities. This update includes 11 critical-severity bugs, primarily involving buffer overflows and use-after-free errors. Specifically, three vulnerabilities were found within the ANGLE component, and one within WebGL. Two additional use-after-free bugs were identified in the GPU component, and another in WebGL. Nine of these critical issues were reported by external researchers, with Google planning to award $18,000 in bug bounty rewards, a figure that could increase significantly as the company evaluates the remaining externally reported bugs. Beyond the critical issues, 25 more vulnerabilities were classified as high-severity, encompassing a variety of problems including use-after-free defects, type confusion, uninitialized resource issues, and buffer overflows. The remaining vulnerabilities are categorized as medium and low severity, relating to authorization, input validation, UI misrepresentation, memory corruption, and information leaks. Google states that it has not yet detected any of these vulnerabilities being actively exploited in the wild, but recommends that users update to the latest version as soon as possible to ensure their systems are protected. Chrome 154 is rolling out for Windows, macOS, and Linux, with versions 154.0.8037.57/.58 and 154.0.8037.57 respectively.