[German]Google has released updates to the Google Chrome browser 112 in the stable channel for Mac and Windows on April 18, 2023. These are security updates that fix critical vulnerabilities. The apps for Android has also been updated.
Advertising
Google Chrome 112.0.5615.137/138
The relevant entry for Chrome 112.0.5615.137/138 can be found on the Google blog. The Extended and Stable channels have been updated to version 112.0.5615.137 for macOS. For Windows, the update updates the browser to version 112.0.5615.137/138. The bug fix updates address 8 vulnerabilities, including those listed below.
- [$8000][1429197] High CVE-2023-2133: Out of bounds memory access in Service Worker API. Reported by Rong Jian of VRI on 2023-03-30
- [$8000][1429201] High CVE-2023-2134: Out of bounds memory access in Service Worker API. Reported by Rong Jian of VRI on 2023-03-30
- [$3000][1424337] High CVE-2023-2135: Use after free in DevTools. Reported by Cassidy Kim(@cassidy6564) on 2023-03-14
- [$NA][1432603] High CVE-2023-2136: Integer overflow in Skia. Reported by Clément Lecigne of Google's Threat Analysis Group on 2023-04-12
- [$1000][1430644] Medium CVE-2023-2137: Heap buffer overflow in sqlite. Reported by Nan Wang(@eternalsakura13) and Guang Gong of 360 Vulnerability Research Institute on 2023-04-05
As usual, no details are given. Google also states that various fixes have been made based on results from internal audits, fuzzing and other initiatives. According to Google, the Google CVE-2023-2136 vulnerability (integer overflow in the Skia graphics engine) is already being exploited in the wild.
Chrome will be rolled out to systems via the automatic update feature in the next few days. One can (and in this case should) also update the browser manually (via the menu and the About Google Chrome command). The latest build of the Chrome browser can also be downloaded here.
Google Chrome 112.0.5615.47/.48 for Android
A Chrome for Android update raises the browser for Android to version 112.0.5615.135/.136, with the updated app rolling out via the Play Store in the coming days.
Advertising