Chrome 126 Updates Patch High-Severity Vulnerabilities

Share This Post

Google on Tuesday announced security updates for Chrome 126 that address ten vulnerabilities, including eight high-severity bugs reported by external researchers.

Despite Google’s efforts to eliminate memory safety bugs in Chrome, most of the externally reported security defects are memory issues that could potentially lead to a sandbox escape and remote code execution.

The new Chrome 126 release resolves an inappropriate implementation flaw in V8, a type confusion in V8, use-after-free bugs in Screen Capture, Media Stream, Audio, and Navigation, a race condition in DevTools, and an out-of-bounds memory access in V8.

Google notes in its advisory that it paid out $10,000 and $7,000 bug bounty rewards for the inappropriate implementation and type confusion vulnerabilities in V8.

The researchers who reported the use-after-free flaws were awarded $6,000, $5,000, $4,000, and $2,500 for their findings, respectively.

In total, Google paid out over $32,000 in bug bounty rewards, but says it has yet to determine the reward amounts to be handed out for the last two externally reported vulnerabilities.

The latest Chrome release is now rolling out as versions 126.0.6478.182/183 for Windows and macOS and as version 126.0.6478.182 for Linux.

On Tuesday, Google also announced that Chrome for Android was updated to version 126.0.6478.186 and that it rolls out to Google Play with the same patches included in the latest desktop releases of the browser.

Advertisement. Scroll to continue reading.

The internet giant makes no mention of any of these vulnerabilities being exploited in the wild, but users are advised to update their browsers as soon as possible.

Related: Chrome 126 Update Patches Memory Safety Bugs

Related: Chrome 126 Update Patches Vulnerability Exploited at Hacking Competition

Related: Google Unveils New Chrome Enterprise Core Features for IT, Security Teams

Related: Chrome 126, Firefox 127 Patch High-Severity Vulnerabilities

This post was originally published on this site

More Articles

Article

Navigating SEC Regulations In Cybersecurity And Incident Response

Free video resource for cybersecurity professionals. As 2024 approaches, we all know how vital it is to keep up to date with regulatory changes that affect our work. We get it – it’s a lot to juggle, especially when you’re in the trenches working on an investigation, handling, and responding to incidents.