HomeSecurityChrome update 131 fixes critical security bugs

Chrome 131 update fixes critical security flaws

Google on Wednesday announced Chrome update 131, which resolves five vulnerabilities, including four high-severity memory security bugs, reported by external researchers.

See also: Google Chrome Updates – Fixes 3 Vulnerabilities

Chrome 131

Known as CVE-2024-12692 , the first of the bugs reported is a type confusion flaw in the browser's V8 JavaScript engine, for which Google paid $55,000 to the researcher who reported it.

While the internet giant has kept details of the bugs limited, such a bug bounty amount is typically given for flaws that could lead to remote code execution (RCE).

Type confusion issues are prevalent in programming languages ​​that lack memory safety mechanisms, and successful exploitation of such flaws in Chrome's V8 engine could allow threat actors to leak sensitive information or compromise the victim's system.

See also: Type Confusion vulnerability in Google Chrome allows remote access

The second reported vulnerability is another memory security issue in V8. It is known as CVE-2024-12693 and was described as an out-of-bounds memory access error, earning the reporting researcher a $20,000 bug bounty reward.

Chrome 131 update fixes critical security flaws

Chrome 131 also addresses CVE-2024-12694, a high-severity issue in Compositing, and CVE-2024-12695, an out-of-bounds write flaw in V8. Google has not disclosed the bug bounty amounts to be paid for these two vulnerabilities.

The latest iteration of Chrome is now available to users as versions 131.0.6778.204/.205 for Windows and macOS, and as version 131.0.6778.204 for Linux. Google makes no mention of whether any of these flaws are actively exploited.

In recent years, Google has taken several steps to make it harder for threat actors to exploit memory security flaws in Chrome, while also investing in eliminating such vulnerabilities from its code base, including moving to Rust, which is considered a memory-safe programming language.

See also: USA: Google must sell the Chrome browser

Memory safety errors are a common and critical class of software vulnerabilities that occur when a program mishandles memory operations. Issues such as buffer overflows or null pointer dereferences often lead to unpredictable behavior, security exploits, and system errors. These errors typically result from low-level programming practices, where programmers manually handle memory allocation and deallocation. Modern programming languages ​​and tools increasingly include features such as garbage collection and bounds checking to mitigate these risks, highlighting the importance of safe memory handling in software development to ensure robust and secure systems.

Source: securityweek

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS