Threat Advisory

Critical Chrome Update Fixes Memory Safety Vulnerability

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Researchers have released a Chrome 128 update addressing five security vulnerabilities, including four reported by external researchers. These issues, classified as high severity, involve memory safety flaws that were disclosed, shortly after Chrome 128 was made available on the stable channel. The first, CVE-2024-8636, is a heap buffer overflow in Skia, Chrome's 2D graphics engine. The second, CVE-2024-8637, is a use-after-free vulnerability in Media Router, which could lead to code execution or denial of service. CVE-2024-8638 is a type of confusion flaw in the V8 JavaScript engine, potentially allowing remote code execution. Lastly, CVE-2024-8639 is another use-after-free bug, this time in the Autofill feature. Google awarded $15,000 and $11,000 in bounties for two of these flaws, with additional rewards pending. Users are urged to update their browsers immediately.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Researchers have released a Chrome 128 update addressing five security vulnerabilities, including four reported by external researchers. These issues, classified as high severity, involve memory safety flaws that were disclosed, shortly after Chrome 128 was made available on the stable channel. The first, CVE-2024-8636, is a heap buffer overflow in Skia, Chrome's 2D graphics engine. The second, CVE-2024-8637, is a use-after-free vulnerability in Media Router, which could lead to code execution or denial of service. CVE-2024-8638 is a type of confusion flaw in the V8 JavaScript engine, potentially allowing remote code execution. Lastly, CVE-2024-8639 is another use-after-free bug, this time in the Autofill feature. Google awarded $15,000 and $11,000 in bounties for two of these flaws, with additional rewards pending. Users are urged to update their browsers immediately.[emaillocker id="1283"]

 

  • CVE-2024-8636: It affects Skia, Chrome's 2D graphics engine. This heap buffer overflow vulnerability could lead to memory corruption or code execution, with a CVSS score of 7.5.

 

  • CVE-2024-8637: It is a use-after-free flaw in the Media Router component. It poses risks of remote code execution, denial-of-service, or data corruption, and has been assigned a CVSS score of 8.1.

 

  • CVE-2024-8638: A type confusion vulnerability in the V8 JavaScript engine, which could cause unexpected application behavior or remote code execution. This vulnerability carries a CVSS score of 8.3.

 

  • CVE-2024-8639: A use-after-free flaw in Autofill, which poses risks such as code execution or browser crashes. This issue has been assigned a CVSS score of 7.8.

RECOMMENDATION:

  • We strongly recommend you update Google Chrome for Linux to version 129.0.6668.70 and for Windows, macOS to version 129.0.6668.70/.71.

REFERENCES:

The following reports contain further technical details:
https://www.securityweek.com/chrome-128-update-resolves-high-severity-vulnerabilities/

[/emaillocker]
crossmenu