Google Chrome Browser (131.0.6778.204/.205) Security Update Advisory

Overview

 

Google has released an update to address a vulnerability in the Chrome(https://www.google.com/chrome) browser. Users of affected versions are advised to update to the latest version.

 

Affected Products

 

Chrome version prior to 131.0.6778.204 (Linux)

Chrome version prior to 131.0.6778.204/.205 (Windows, Mac)

 

Resolved Vulnerabilities

 

High-level memory free and reuse (UAF) vulnerability in the Compositing feature (CVE-2024-12694) [1]

High Level Type Confusion Vulnerability in V8 Functionality (CVE-2024-12692) [1

High Level Out-of-Bounds Memory Access Vulnerability in V8 Functionality (CVE-2024-12693) [1]

High Level Out-of-Bounds Write Vulnerability in V8 Functionality (CVE-2024-12695) [1]

 

Vulnerability Patches

 

The December 18, 2024 update provided the following Vulnerability Patches. For more information on Vulnerability Patches, please refer to the “Google Chrome” Referenced Sites document.

Chrome 131.0.6778.204/.205 or later version (Windows, Mac)

Chrome 131.0.6778.204 or later version (Linux)

 

Referenced Sites

 

[1] Stable Channel Update for Desktop

https://chromereleases.googleblog.com/2024/12/stable-channel-update-for-desktop_18.html

[2] Chrome Update

https://support.google.com/chrome/answer/95414?co=GENIE.Platform%3DDesktop