news4geeks.net
2May/120

Chrome 18 update closes high-risk security holes


Google Chrome logo Google has released a new update to the stable 18.x branch of its Chrome web browser to close a number of security holes found in the application. The update, labelled 18.0.1025.168, addresses a total of five vulnerabilities, three of which are rated as "high severity" by the company.

These include use-after-free problems in floating point handling and the XML parser; all of these bugs were detected using the AddressSanitizer. As part of its Chromium Security Vulnerability Rewards program, Google paid a security researcher by the name of "miaubiz", who is number three in the company's Security Hall of Fame, $1,000 for discovering and reporting one of the float handling problems. Two medium risk problems related to IPC validation and a race condition in sandbox IPC have also been corrected.

Further information about the update can be found in the announcement post on the Google Chrome Releases blog. Chrome 18.0.1025.168 is available to download for Windows, Mac OS X and Linux from google.com/chrome; existing users can upgrade using the built-in update function.

(Source: h-online.com)

 

The companies betting that we'll want to manipulate everything electronic around us with a wave of a hand are already laying claim to various types of body movement. The ...
READ MORE
A patent application filed by Google last year provides a detailed look at some of the metrics the company considers when ranking news stories and deciding how prominently ...
READ MORE
The U.S. Department of Homeland Security (DHS) has issued an alert warning of vulnerabilities in a software technology called the Niagara AX Framework, used to manage millions of ...
READ MORE
Attack code for two actively exploited vulnerabilities in Microsoft software, one of which has not yet been patched, was integrated into the open source Metasploit penetration testing framework. One ...
READ MORE
Google boosts Web bug bounties to $20,000
Google today dramatically raised the bounties it pays independent researchers for reporting bugs in its core websites, services and online applications. The search giant boosted the maximum reward from ...
READ MORE
Hands up who wants 3D finger-controlled fridges? That’s
An inside look at Google’s news-ranking algorithm
DHS warns of vulnerabilities in widely used Niagara
Attack code published for two actively exploited vulnerabilities
Google boosts Web bug bounties to $20,000

Comments (0) Trackbacks (0)

No comments yet.


Leave a comment

Trackbacks are disabled.