Google Chrome: multiple “high” criticality vulnerabilities discovered in the browser


Alexandre Boero

Clubic news manager

March 6, 2024 at 6:56 p.m.

0

Google Chrome open on smartphone © photosince / Shutterstock.com

Google Chrome open on smartphone © photosince / Shutterstock.com

The giant Google has published a new security advisory, revealing several vulnerabilities in the Chrome browser. The Mountain View firm considers the critical level to be “high”.

Notice to Google Chrome users: the web browser is subject to three security vulnerabilities. Referenced CVE-2024-2173, CVE-2024-2174 and CVE-2024-2176, they affect versions of Chrome for Windows, Mac and Linux. The American company is in the process of deploying an update that we advise you to install as soon as possible.

Three security vulnerabilities that are the subject of an update to be installed quickly

The three vulnerabilities, which respectively brought in $6,000, $7,000 and $12,000 to those who were able to discover them, affect several versions of the browser, with a criticality level set as “high” each time. Here is the list :

  • Google Chrome versions prior to 122.0.6261.111/.112 for Windows,
  • Google Chrome versions prior to 122.0.6261.111 for Linux and Mac,
  • Google Chrome Extended Stable versions prior to 122.0.6261.112 for Windows and Mac

The flaws allow a cybercriminal to cause a security issue that, as usual, was not specified by the company. What we know is that they are the subject of an update which therefore includes three security fixes.

Google Chrome on an iPhone screen © 2lttgamingroom / Shutterstock.com

Google Chrome on an iPhone screen © 2lttgamingroom / Shutterstock.com

Google invites its users to update their browser

We still know that for the CVE-2024-2173 vulnerability, it is a “ memory access out of bounds in V8 ”, which corresponds to Chrome’s JavaScript engine. The CVE-2024-2174 flaw evokes a “ inappropriate implementation in V8 “.

As for the CVE-2024-2176 breach, Google mentions a “ free use in FedCM “, a specification that can make it easier to sign in to websites through federated identity services, such as signing in through Google, GitHub, and other services.

To update Google Chrome to versions 122.0.6261.111/112, which are not affected by these vulnerabilities, here is the path to follow:

  • Click on the three small dots (…) at the top right of the browser,
  • Select “Help”, then “About Google Chrome”,
  • And you will just have to let the browser install the latest updated version.

Google Chrome

Download

Read the review


7.8

Google Chrome

  • Very good performance
  • Simple and pleasant to use
  • A well-secured browser

Complete and fluid, Google Chrome has established itself as a free reference for web browsers and is in an excellent position compared to other flagship applications such as Mozilla Firefox and Microsoft Edge (formerly Internet Explorer). To complete its Windows, Mac and Linux version for computers, the Californian firm also offers a mobile version compatible with Android and iOS.

Complete and fluid, Google Chrome has established itself as a free reference for web browsers and is in an excellent position compared to other flagship applications such as Mozilla Firefox and Microsoft Edge (formerly Internet Explorer). To complete its Windows, Mac and Linux version for computers, the Californian firm also offers a mobile version compatible with Android and iOS.

Best antivirus, comparison in March 2024
To discover
Best antivirus, comparison in March 2024

March 1, 2024 at 09:08

Service comparisons

Sources: Google, ANSSI

Alexandre Boero

Alexandre Boero

Clubic news manager

Clubic news manager

Journalist, responsible for CLUBIC news. Reporter, videographer, host and even singer-imitator, I wrote my first article in 6th grade. I made this vocation my profession (graduated from the EJC...

Read other articles

Journalist, responsible for CLUBIC news. Reporter, videographer, host and even singer-imitator, I wrote my first article in 6th grade. I made this vocation my job (graduated from EJCAM), to write, interview, film, edit and produce on a daily basis. Friendships with Tech, of course, but also with the world of media, sport and travel. In addition to journalism, video production and animation, I have a YouTube channel (in my name) which should pique your curiosity if you like beautiful walks around the world, new technologies and Koh-Lanta 🙂

Read other articles





Source link -99