Google Chrome Browser (123.0.6312.105) Security Update Advisory

Overview

 

Google provides Chrome (https://www.google.com/chrome) browser to address a vulnerability. users of affected versions are advised to update to the latest version.

 

Affected Products

 

Cve-2024-3156, cve-2024-3158, cve-2024-3159

  • Google Chrome versions prior to 123.0.6312.105

 

Resolved Vulnerabilities

 

Out-of-bounds memory access vulnerability via a crafted HTML page in Chrome v8 (CVE-2024-3156)

Heap corruption via a crafted HTML page when using user-after-free in bookmarks in Chrome (CVE-2024-3158)

Out-of-bounds memory access in Chrome v8 allows arbitrary read/write via HTML page (CVE-2024-3159)

 

Vulnerability Patches

 

The following Vulnerability Patches were made available in the April 2, 2024 update. For more information on Vulnerability Patches, please refer to the “Google Chrome” Referenced Sites document.

  • Google Chrome version 123.0.6312.105/.106/.107 for Windows/Mac
  • Google Chrome version 123.0.6312.105 for Linux

 

Referenced Sites

 

[1] CVE-2024-3156 Detail

https://nvd.nist.gov/vuln/detail/CVE-2024-3156

[2] CVE-2024-3158 Detail

https://nvd.nist.gov/vuln/detail/CVE-2024-3158

[3] CVE-2024-3159 Detail

https://nvd.nist.gov/vuln/detail/CVE-2024-3159

[4] Stable Channel Update for Desktop

https://chromereleases.googleblog.com/2024/04/stable-channel-update-for-desktop.html