 [German]Short addendum, I have not gotten to it yet. Google has already released updates of the Google Chrome browser 110 in the stable channel for Mac, Linux and Windows until February 7, 2023. Thanks to Robert for the hint.
[German]Short addendum, I have not gotten to it yet. Google has already released updates of the Google Chrome browser 110 in the stable channel for Mac, Linux and Windows until February 7, 2023. Thanks to Robert for the hint.
Google Chrome Chrome 109.0.5414.119/.120
The relevant entry for Chrome 110 can be found on the Google blog. The stable channel has been updated to version 110.0.5481.77 for macOS and Linux. For Windows, the update updates the browser to version 110.0.5481.77/.78. The bug fix updates close 15 vulnerabilities, including those listed below.
- [$7000][1402270] High CVE-2023-0696: Type Confusion in V8. Reported by Haein Lee at KAIST Hacking Lab on 2022-12-18
- [$4000][1341541] High CVE-2023-0697: Inappropriate implementation in Full screen mode. Reported by Ahmed ElMasry on 2022-07-03
- [$2000][1403573] High CVE-2023-0698: Out of bounds read in WebRTC. Reported by Cassidy Kim(@cassidy6564) on 2022-12-25
- [$3000][1371859] Medium CVE-2023-0699: Use after free in GPU. Reported by 7o8v and Cassidy Kim(@cassidy6564) on 2022-10-06
- [$3000][1393732] Medium CVE-2023-0700: Inappropriate implementation in Download. Reported by Axel Chong on 2022-11-26
- [$2000][1405123] Medium CVE-2023-0701: Heap buffer overflow in WebUI. Reported by Sumin Hwang of SSD Labs on 2023-01-05
- [$1500][1316301] Medium CVE-2023-0702: Type Confusion in Data Transfer. Reported by Sri on 2022-04-14
- [$1000][1405574] Medium CVE-2023-0703: Type Confusion in DevTools. Reported by raven at KunLun lab on 2023-01-07
- [$2000][1385982] Low CVE-2023-0704: Insufficient policy enforcement in DevTools. Reported by Rhys Elsmore and Zac Sims of the Canva security team on 2022-11-18
- [$1000][1238642] Low CVE-2023-0705: Integer overflow in Core. Reported by SorryMybad (@S0rryMybad) of Kunlun Lab on 2021-08-11
As usual, no details are given. Google also states that various fixes have been made based on results from internal audits, fuzzing and other initiatives. Chrome will be rolled out to systems via the automatic update feature in the next few days. One can (and in this case should) also update the browser manually (via the menu and the About Google Chrome command). The latest build of the Chrome browser can also be downloaded here.
Note: Chrome 110 no longer runs on Windows 7 SP1 or Windows 8.1 as well as the server counterparts (see Windows 7/8.1: Google ends support in February 2023, Edge also affected). In addition, Google Chrome will be distributed as a staged rollout starting with this version (see Chrome 110 will be released as a staged rollout).
 
			


