Multiple Vulnerabilities in Google Chrome for Desktop

Original Issue Date: April 29, 2022

Severity Rating: HIGH

Software Affected

Google Chrome version prior to 101.0.4951.41

Overview

Multiple vulnerabilities have been reported in Google Chrome which could allow a remote attacker to execute arbitrary code, obtain sensitive information, bypass security restrictions and cause buffer overflow on the targeted system.

Description

These vulnerabilities exist in Google Chrome due to Use after free in Vulkan, Swift Shader, ANGLE, Device API, Sharing, File System API, Ozone, Browser Switcher, Bookmarks, Dev Tools and File Manager; Inappropriate implementation in WebGL, Extensions API, Input, HTML Parser, Web Authentication and iframe; Heap buffer overflow in Web GPU and Web UI Settings; Type Confusion in V8; Out of bounds memory access in UI Shelf; Insufficient data validation in Blink Editing, Trusted Types and Dev

Tools; Incorrect security UI in Downloads.

Successful exploitation of these vulnerabilities could allow a remote attacker to execute arbitrary code in the context of the browser, obtain sensitive information, bypass security restrictions and cause buffer overflow on the targeted system.

Solution

Upgrade to Google chrome version 101.0.4951.41as mentioned at

https://chromereleases.googleblog.com/2022/04/stable-channel-update-for-desktop_26.html

Leave a Reply