Google fixes 26 vulnerabilities in Chrome 97, including one critical

Spread the love

Google has fixed 26 bugs in the new version of Chrome. One of them will receive the ‘Critical’ label. That’s a use-after-free in the browser discovered by Google’s own researchers.

The changes are in version 97.0.4692.99 of the browser. That’s the stable version. The same bug fixes have also been implemented in the extended stable channel. That is version 96.0.4664.110 for Windows and macOS. A total of 26 bug fixes have been implemented in the versions. Sixteen of these have a ‘High’ rating, and another six are rated ‘Medium’. This concerns bugs discovered by external researchers and passed on to Google.

A lot of the bugs are use-after-free vulnerabilities. These were included in the Vulkan rendering engine, in Omnibox and in the print function. There were also several heap buffer overflows in the browser.

The most serious bug is CVE-2022-0289. It is marked as ‘Critical’, although details about it are not publicly known. It is a use-after-free in the Safe Browsing feature. The bug was discovered by a researcher on Google’s own Project Zero bug-hunting team. Google does not write anywhere whether the vulnerabilities are exploited in the wild. When that happens, the company usually mentions it.

You might also like