Final week, Google launched Chrome 128 and patched a zero-day vulnerability with it. Now, Google has launched updates to Chrome 128 that repair 4 safety vulnerabilities (none of which have been exploited within the wild but). Different Chromium-based browsers are prone to observe quickly.
Within the Chrome Releases weblog replace, Prudhvikumar Bommana lists the 4 patched vulnerabilities that have been found by exterior safety researchers and reported to Google.
All 4 vulnerabilities are categorized as “excessive threat” by Google. The sort confusion difficulty within the V8 JavaScript engine was included twice this week (CVE-2024-7969, CVE-2024-8194). The opposite two vulnerabilities are additionally siblings: they’re buffer overflows within the open-source 2D graphics library Skia (CVE-2024-8193, CVE-2024-8198).
Chrome normally updates itself mechanically when a brand new model is accessible, but when your browser hasn’t up to date but, you’ll be able to set off it with a handbook replace verify: open the three-dot menu and navigate to Assist > About Google Chrome.
Different Chromium-based browsers
As of now, different Chromium-based browsers are nonetheless catching up. Courageous and Microsoft Edge have already made the swap to Chromium 128 however are solely as much as final week’s safety stage.
In the meantime, Opera model 113 solely simply switched to Chromium 127, Vivaldi model 6.8 nonetheless depends on the Prolonged Steady Channel of Chromium model 126, and Vivaldi model 6.9 is up-to-date because it’s now primarily based on the newest Chromium 128.
All 4 browsers are secured in opposition to the CVE-2024-7971 zero-day vulnerability from the earlier week.
Additional studying: Tricks to make Google Chrome safer
This text initially appeared on our sister publication PC-WELT and was translated and localized from German.