Google has released a Chrome 150 security update that resolves seven memory safety bugs, including critical and high-severity use-after-free vulnerabilities.
The browser refresh patches three critical-severity use-after-free flaws impacting Chrome’s CameraCapture, GPU, and Network components. All three weaknesses were discovered by Google.
Additionally, the update fixes three high-severity use-after-free issues in Cast, Ozone, and Aura; Google discovered these vulnerabilities as well.
The seventh security defect is an out-of-bounds read and write flaw in the V8 JavaScript engine that was identified by OpenAI Codex Security. Google has yet to determine the bug bounty amount to be paid for the finding.
Google makes no mention of any of these security defects being exploited in the wild, but users are advised to update their browsers as soon as possible, as threat actors have targeted memory safety issues in Chrome.
For years, the internet giant has been hardening the browser against the exploitation of memory safety bugs, including by transitioning to memory-safe programming languages such as Rust.
Since April, the internet giant has patched over 1,400 Chrome vulnerabilities, including hundreds of memory safety flaws, most of which were discovered by Google, likely through the use of AI.
The latest Chrome iteration is now rolling out as versions 150.0.7871.128/.129 for Windows and macOS and as version 150.0.7871.128 for Linux.
Related: Critical Vulnerabilities Patched With Fresh Chrome 150, Firefox 152 Updates
Related: WP2Shell WordPress Vulnerabilities Exploited in the Wild
Related: Fresh SharePoint Vulnerability Exploited Soon After Disclosure
Related: Legacy Systems, Real-World Impacts: The Reality of OT Security
