EXECUTIVE SUMMARY:
Researchers have released a Chrome 128 update addressing five security vulnerabilities, including four reported by external researchers. These issues, classified as high severity, involve memory safety flaws that were disclosed, shortly after Chrome 128 was made available on the stable channel. The first, CVE-2024-8636, is a heap buffer overflow in Skia, Chrome's 2D graphics engine. The second, CVE-2024-8637, is a use-after-free vulnerability in Media Router, which could lead to code execution or denial of service. CVE-2024-8638 is a type of confusion flaw in the V8 JavaScript engine, potentially allowing remote code execution. Lastly, CVE-2024-8639 is another use-after-free bug, this time in the Autofill feature. Google awarded $15,000 and $11,000 in bounties for two of these flaws, with additional rewards pending. Users are urged to update their browsers immediately.[/subscribe_to_unlock_form]
EXECUTIVE SUMMARY:
Researchers have released a Chrome 128 update addressing five security vulnerabilities, including four reported by external researchers. These issues, classified as high severity, involve memory safety flaws that were disclosed, shortly after Chrome 128 was made available on the stable channel. The first, CVE-2024-8636, is a heap buffer overflow in Skia, Chrome's 2D graphics engine. The second, CVE-2024-8637, is a use-after-free vulnerability in Media Router, which could lead to code execution or denial of service. CVE-2024-8638 is a type of confusion flaw in the V8 JavaScript engine, potentially allowing remote code execution. Lastly, CVE-2024-8639 is another use-after-free bug, this time in the Autofill feature. Google awarded $15,000 and $11,000 in bounties for two of these flaws, with additional rewards pending. Users are urged to update their browsers immediately.[emaillocker id="1283"]
RECOMMENDATION:
REFERENCES:
The following reports contain further technical details:
https://www.securityweek.com/chrome-128-update-resolves-high-severity-vulnerabilities/