Google Chrome Browser (131.0.6778.204/.205) Security Update Advisory
Overview
Google has released an update to address a vulnerability in the Chrome(https://www.google.com/chrome) browser. Users of affected versions are advised to update to the latest version.
Affected Products
Chrome version prior to 131.0.6778.204 (Linux)
Chrome version prior to 131.0.6778.204/.205 (Windows, Mac)
Resolved Vulnerabilities
High-level memory free and reuse (UAF) vulnerability in the Compositing feature (CVE-2024-12694) [1]
High Level Type Confusion Vulnerability in V8 Functionality (CVE-2024-12692) [1
High Level Out-of-Bounds Memory Access Vulnerability in V8 Functionality (CVE-2024-12693) [1]
High Level Out-of-Bounds Write Vulnerability in V8 Functionality (CVE-2024-12695) [1]
Vulnerability Patches
The December 18, 2024 update provided the following Vulnerability Patches. For more information on Vulnerability Patches, please refer to the “Google Chrome” Referenced Sites document.
Chrome 131.0.6778.204/.205 or later version (Windows, Mac)
Chrome 131.0.6778.204 or later version (Linux)
Referenced Sites
[1] Stable Channel Update for Desktop
https://chromereleases.googleblog.com/2024/12/stable-channel-update-for-desktop_18.html
[2] Chrome Update
https://support.google.com/chrome/answer/95414?co=GENIE.Platform%3DDesktop