A security update for Google Chrome 96 is out
#1
Information 
Quote:
[Image: chrome-96-security-update.webp]

Google released an update for Google Chrome 96, the company's web browser, today for all supported desktop operating systems and for the company's Android platform.The new version of Google Chrome is a security update that patches 20 different security issues, many of which rated high, the second-highest rating after critical.

Chrome is rolled out automatically on all supported platforms by default. Desktop users may speed up the discovery of the new update by selecting Menu > Help > About Google Chrome, or by loading chrome://settings/help directly. The page that opens lists the version of the browser that is installed currently, and it will run a check for updates to download and install the latest version of the browser.

Android users may open the page as well, but the download of updates is powered by Google Play, which means that updates can't be expedited this way.

The Chrome releases blog lists all security issues that were reported by external researchers. Most were reported to Google in November, some in October and one in August of 2021.
 
Quote:[$15000][1267661] High CVE-2021-4052: Use after free in web apps. Reported by Wei Yuan of MoyunSec VLab on 2021-11-07
[$10000][1267791] High CVE-2021-4053: Use after free in UI. Reported by Rox on 2021-11-08
[$5000][1239760] High CVE-2021-4054: Incorrect security UI in autofill. Reported by Alesandro Ortiz on 2021-08-13
[$1000][1266510] High CVE-2021-4055: Heap buffer overflow in extensions. Reported by Chen Rong on 2021-11-03
[$TBD][1260939] High CVE-2021-4056: Type Confusion in loader. Reported by @__R0ng of 360 Alpha Lab on 2021-10-18
[$TBD][1262183] High CVE-2021-4057: Use after free in file API. Reported by Sergei Glazunov of Google Project Zero on 2021-10-21
[$TBD][1267496] High CVE-2021-4058: Heap buffer overflow in ANGLE. Reported by Abraruddin Khan and Omair on 2021-11-06
[$TBD][1270990] High CVE-2021-4059: Insufficient data validation in loader. Reported by Luan Herrera (@lbherrera_) on 2021-11-17
[$TBD][1271456] High CVE-2021-4061: Type Confusion in V8. Reported by Paolo Severini on 2021-11-18
[$TBD][1272403] High CVE-2021-4062: Heap buffer overflow in BFCache. Reported by Leecraso and Guang Gong of 360 Alpha Lab on 2021-11-22
[$TBD][1273176] High CVE-2021-4063: Use after free in developer tools. Reported by Abdulrahman Alqabandi, Microsoft Browser Vulnerability Research on 2021-11-23
[$TBD][1273197] High CVE-2021-4064: Use after free in screen capture. Reported by @ginggilBesel on 2021-11-23
[$TBD][1273674] High CVE-2021-4065: Use after free in autofill. Reported by 5n1p3r0010 on 2021-11-25
[$TBD][1274499] High CVE-2021-4066: Integer underflow in ANGLE. Reported by Jaehun Jeong(@n3sk) of Theori on 2021-11-29
[$TBD][1274641] High CVE-2021-4067: Use after free in window manager. Reported by @ginggilBesel on 2021-11-29
[$500][1265197] Low CVE-2021-4068: Insufficient validation of untrusted input in new tab page. Reported by NDevTK on 2021-10-31

No critical rating has been assigned, but most issues are rated as high. The issues don't seem to be exploited in the wild, as Google mentions that usually in the release announcement.

The Android version includes stability and performance updates according to Google. It is unclear if security issues were patched in the Android version as well; none are mentioned on the release blog post.

Most Chromium-based browsers are affected by at least some of these vulnerabilities as well. Expect other browsers, such as Microsoft Edge or Brave, to release security updates soon as well that address the issues.

Now You: When do you update your browsers?
...
Continue Reading
Reply


Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
QOwnNotes
26.4.6  Fixed a w...Kool — 08:36
INTEL Arc Graphics 32.0.101.8629 driver
Highlights: Int...harlan4096 — 07:57
Qualcomm Snapdragon X2 Elite Review Rou...
Snapdragon X2 Elite ...harlan4096 — 07:55
Qualcomm Snapdragon X2 Elite Review Roun...
Snapdragon X2, sec...harlan4096 — 07:55
Mozilla Firefox Browser 149.0.2
149.0.2 Firefox Re...harlan4096 — 07:52

[-]
Birthdays
Today's Birthdays
avatar (39)vemedProkbior
Upcoming Birthdays
avatar (45)wapedDow
avatar (49)oapedDow
avatar (42)Sanchowogy
avatar (46)MeighGoask
avatar (38)urumahiz
avatar (44)techlignub
avatar (43)Stevenmam
avatar (50)onlinbah
avatar (50)fuspeukChark
avatar (44)werriewWaiNg
avatar (38)Freemanleo
avatar (43)cdoubapKit
avatar (38)lystraPonia
avatar (31)smith8395john
avatar (51)steakelask
avatar (45)Termoplenka
avatar (43)bycoPaist
avatar (49)pieloKat
avatar (43)ilyagNeexy
avatar (51)donitascene
avatar (51)burntLaw
avatar (41)MrDoorsskibheeds
avatar (51)Toligo
avatar (46)Rodneykak
avatar (49)tradeSmode
avatar (38)RobertUtelt
avatar (36)Kiran78

[-]
Online Staff
There are no staff members currently online.

>