Skip to content
Chrome 154 fixes 108 security flaws, including 11 critical bugs

Chrome 154 fixes 108 security flaws, including 11 critical bugs

In the newest versions of Chrome—154.0.8037.57/58 for Windows and macOS, and 154.0.8037.57 for Linux—Google has fixed 108 security vulnerabilities, some of which are critical. None of them have been exploited in attacks yet. Meanwhile, Chrome 154 doesn’t offer any new features beyond these security improvements.

In the Chrome Releases blog post, Srinivas Sista lists the 108 vulnerabilities that have been fixed, stating that Google discovered 76 of them. The remaining 32 vulnerabilities were identified and reported by external security researchers, and Google has so far awarded them a total of $18,000 in bounties.

Eleven vulnerabilities are classified as critical, with three of them being buffer overflows in the Angle graphics library for WebGL. A further 25 vulnerabilities are classified as high risk, 47 as medium risk, and 25 as low risk. The most common types of fixed security vulnerabilities are use-after-free flaws (34), UI misrepresentation issues (12), incorrect authorizations (12), and missing authorizations (11).

Chrome usually updates automatically when a new version is available. You can manually check for updates via the menu in Help → About Google Chrome (alternatively, Settings → About Google Chrome).

Google has also released Chrome for Android 154.0.8037.57 and Chrome for iOS 154.0.8037.55 this week. The Android version addresses the same vulnerabilities as the desktop versions. The Extended Stable Channel for Windows and macOS now includes Chromium 152.0.7977.140.

Chrome 155 is due to release in about two weeks.

Tip: Whether you keep your browser up to date, you need proper antivirus protections if you want your PC to remain secure and private. Check out our picks for the best antivirus software for Windows as well as best VPN services to stay ahead of security problems.

Source link