Google Chrome browser (128.0.6613.137/.138) security update advisory

Overview

 

Google has released an update to address a vulnerability in the Chrome(https://www.google.com/chrome) browser. Users of affected versions are advised to update to the latest version.

 

Affected Products

 

Chrome version prior to 128.0.6613.137 (Linux)

Chrome version prior to 128.0.6613.137/.138 (Windows)

 

Resolved Vulnerabilities

 

High-level memory free and reuse (UAF) vulnerability in the Autofill function (CVE-2024-8639) [1]

High level memory free and reuse (UAF) vulnerability in the Media router function (CVE-2024-8637) [1]

High Level Heap Buffer Overflow Vulnerability in Skia Functionality (CVE-2024-8636) [1]

High Level Type Confusion Vulnerability in V8 Functionality (CVE-2024-8638) [1

 

Vulnerability Patches

 

The following Vulnerability Patches were made available in the 09/10/2024 update. For more information on Vulnerability Patches, Please refer to the “Google Chrome” Referenced Sites document.

Chrome 128.0.6613.137/.138 or later (Windows)

Chrome 128.0.6613.137 or later (Linux)

 

Referenced Sites

 

[1] Stable Channel Update for Desktop

https://chromereleases.googleblog.com/2024/09/stable-channel-update-for-desktop_10.html

[2] Chrome Update

https://support.google.com/chrome/answer/95414?co=GENIE.Platform%3DDesktop