Google has released a critical security update for its Chrome browser, addressing multiple high-severity vulnerabilities that could allow attackers to execute malicious code on users’ systems.
The update, version 127.0.6533.99/.100 for Windows and Mac, and 127.0.6533.99 for Linux, was announced on August 6, 2024, and is currently being rolled out to users worldwide.
The most severe of these vulnerabilities, CVE-2024-7532, is classified as critical and involves an out-of-bounds memory access in ANGLE (Almost Native Graphics Layer Engine).
Are you from SOC and DFIR Teams? – Analyse Malware Incidents & get live Access with ANY.RUN -> Free Access
This flaw could allow attackers to execute arbitrary code or cause system crashes, posing a significant risk to users’ security and privacy.
In addition to the critical vulnerability, the update addresses five high-severity issues:
Malicious actors could potentially exploit these vulnerabilities to gain unauthorized access to users’ systems, steal sensitive information, or execute arbitrary code.
Google has not disclosed specific details about the vulnerabilities to prevent further exploitation, as is common practice until a majority of users have updated their browsers.
The company has awarded substantial bug bounties to the security researchers who reported these flaws, with one researcher receiving $11,000 for identifying the Sharing vulnerability.
Users are strongly advised to update their Chrome browsers immediately to the latest version to protect themselves from potential attacks. To update Chrome:
This incident serves as a reminder of the ongoing importance of keeping software up-to-date and the critical role that security researchers play in identifying and reporting vulnerabilities.
As cyber threats continue to evolve, prompt patching and vigilant security practices remain essential for maintaining online safety.
How to Build a Security Framework With Limited Resources IT Security Team (PDF) - Free Guide
Microsoft has pushed out an emergency, out-of-band Windows 11 update after its September Patch Tuesday…
CDR is the runtime, real-time half of cloud security: while CSPM tells you what’s misconfigured,…
Your SaaS estate M365, Salesforce, Workday, Slack, hundreds of others is a sprawl of misconfigurations,…
DSPM finds sensitive data you didn’t know you had, classifies it, maps who can reach…
Open-source packages are meant to save developers time. In the GemStuffer campaign, that trust became…
Google has released an important Chrome 153 security update that fixes 42 vulnerabilities across the…