HomeUpdatesGoogle: Chrome 101 fixes serious vulnerabilities

Google: Chrome 101 fixes serious vulnerabilities

Google announced this week that Chrome version 101 has been released to the stable channel, bringing fixes for 30 vulnerabilities . Of those vulnerabilities , 25 were discovered by external security researchers , and at least seven are considered very serious . The bugs affect Chrome on Windows , macOS , Linux , and mobile .

The most important of the fixes in Chrome 101 resolves a high-severity use-after-free bug in the open standard Vulkan. The vulnerability is known as CVE-2022-1477 and was reported by SeongHwan Park (SeHwa), who received a $10,000 reward under the company's bug bounty program.

See also: Lenovo patches three UEFI firmware vulnerabilities

Google Chrome 101 vulnerabilities

Chrome 101 fixes four more use-after-free bugs, affecting SwiftShader 3D, Angle, Device API, and Sharing.

Google says it paid out $7,000 in bug bounties for each of the bugs in SwiftShader and Angle, and that it handed out rewards of $6,000 and $5,000 for the issues affecting the Device API and Sharing, respectively.

The other two high-severity bugs addressed in the latest version of Chrome are a problem in WebGL and a Heap buffer overflow vulnerability in WebGPU.

These issues were reported by Christoph Diehl from Microsoft and Mark Brand from Google Project Zero. In accordance with Google 's policies , no rewards will be given for revealing these two bugs.

See also: Aethon: Critical vulnerabilities in hospital robots – Fixed

However, the internet giant says that 15 of the remaining issues reported by external researchers qualify for bug bounty rewards.

In detail, the 7 very serious vulnerabilities that the new Chrome version 101 fixes:

  • CVE-2022-1477: Use after free bug in Vulkan. Reported by SeongHwan Park (SeHwa) on April 6.
  • CVE-2022-1478: Use after free bug in SwiftShader. Reported by SeongHwan Park (SeHwa) on February 20.
  • CVE-2022-1479: Use after free bug in ANGLE. Reported by Jeonghoon Shin on March 10.
  • CVE-2022-1480: Use after free bug in Device API. Reported by @uwu7586 on March 17.
  • CVE-2022-1481: Use after free bug in Sharing. Reported by Weipeng Jiang (@Krace) and Guang Gong on March 4.
  • CVE-2022-1482: Inappropriate implementation in WebGL. Reported by Christoph Diehl, Microsoft on March 10.
  • CVE-2022-1483: Heap buffer overflow in WebGPU. Reported by Mark Brand of Google Project Zero on April 8.
Google: Chrome 101 fixes serious vulnerabilities

The latest version of Chrome is now available to Windows, macOS, and Linux users as Chrome 101.0.4951.41.

See also: April Patch Tuesday: Microsoft fixes 119 vulnerabilities

You can check if the update is available by following these steps:

  • Click the three dots in the top right corner of Chrome.
  • Click Settings > Help > About Google Chrome.
  • Wait for Chrome to find and install the update.
  • When prompted, restart Chrome.
📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS