» » Chrome 109 Patches 17 Vulnerabilities

Chrome 109 Patches 17 Vulnerabilities

Chrome 109 Patches 17 Vulnerabilities

House › Vulnerabilities

Chrome 109 Patches 17 Vulnerabilities

By Ionut Arghire on January 11, 2023

Tweet

Google on Tuesday introduced the discharge of Chrome 109 within the secure channel with patches for 17 vulnerabilities, together with 14 bugs reported by exterior researchers.

Many of the externally reported safety defects are medium- and low-severity flaws, with solely two of them rated ‘excessive severity’.

These embody a use-after-free situation in Overview Mode (CVE-2023-0128), and a heap buffer overflow bug in Community Service (CVE-2023-0129). Google says it paid bug bounties of $4,000 and $2,000 for these vulnerabilities, respectively.

A complete of eight medium-severity bugs had been resolved with the most recent browser iteration, 5 of that are described as inappropriate implementation flaws in Chrome elements reminiscent of Fullscreen API, Iframe Sandbox, and Permission Prompts.

The remaining points embody two use-after-free vulnerabilities in Cart and a heap buffer overflow bug in Platform Apps.

Chrome 109 additionally patches 4 externally reported low-severity vulnerabilities.

Apparently, Google notes that the very best bug bounty reward was paid out for one of many low-severity points addressed this week, specifically CVE-2023-0138, a heap buffer overflow bug within the libphonenumber element.

The researcher who recognized this situation obtained a $8,000 reward, whereas the very best bug bounty for a medium-severity situation was $5,000.

In whole, Google paid out $39,000 in bug bounty rewards to the reporting researchers, however the closing quantity could be increased, as the corporate has but to find out the reward for one of many medium-severity points.

The newest Chrome iteration is presently rolling out as model 109.0.5414.74 for Linux, model 109.0.5414.74/.75 for Home windows, and model 109.0.5414.87 for macOS.

Google made no point out about any of those vulnerabilities being exploited in malicious assaults. Final 12 months, the web big patched 9 zero-days within the browser.

Associated: Chrome 108 Patches Excessive-Severity Reminiscence Security Bugs

Associated: Google Pays $45,000 for Excessive-Severity Vulnerabilities Present in Chrome

Associated: Google Pays Out Over $50,000 for Vulnerabilities Patched by Chrome 107

Get the Every day Briefing

 
 
 

  • Most Current
  • Most Learn
  • Chrome 109 Patches 17 Vulnerabilities
  • Cybercrime Group Exploiting Previous Home windows Driver Vulnerability to Bypass Safety Merchandise
  • British Manufacturing Agency Morgan Superior Supplies Investigating Cyberattack
  • 251ok Impacted by Knowledge Breach at Insurance coverage Agency Bay Bridge Directors
  • SAP’s First Safety Updates for 2023 Resolve Essential Vulnerabilities
  • Unpatchable {Hardware} Vulnerability Permits Hacking of Siemens PLCs
  • EU Tells TikTok Chief To Respect Knowledge Privateness Legal guidelines
  • Microsoft Patch Tuesday: 97 Home windows Vulns, 1 Exploited Zero-Day
  • Intel Provides TDX to Confidential Computing Portfolio With Launch of 4th Gen Xeon Processors
  • Adobe Plugs Safety Holes in Acrobat, Reader Software program

On the lookout for Malware in All of the Incorrect Locations?

First Step For The Web’s subsequent 25 years: Including Safety to the DNS

Tattle Story: What Your Pc Says About You

Be in a Place to Act By way of Cyber Situational Consciousness

Report Exhibits Closely Regulated Industries Letting Social Networking Apps Run Rampant

2010, A Nice Yr To Be a Scammer.

Do not Let DNS be Your Single Level of Failure

Methods to Determine Malware in a Blink

Defining and Debating Cyber Warfare

The 5 A’s that Make Cybercrime so Engaging

Methods to Defend Towards DDoS Assaults

Safety Budgets Not in Line with Threats

Anycast – Three Causes Why Your DNS Community Ought to Use It

The Evolution of the Prolonged Enterprise: Safety Methods for Ahead Considering Organizations

Utilizing DNS Throughout the Prolonged Enterprise: It’s Dangerous Enterprise

SecurityWeek Podcast

author-Orbit Brain
Orbit Brain
Orbit Brain is the senior science writer and technology expert. Our aim provides the best information about technology and web development designing SEO graphics designing video animation tutorials and how to use software easy ways
and much more. Like Best Service Latest Technology, Information Technology, Personal Tech Blogs, Technology Blog Topics, Technology Blogs For Students, Futurism Blog.

Cyber Security News Related Articles