Security News > 2021 > August > Google Patches Several Chrome Flaws That Can Be Exploited via Malicious Extensions

Google Patches Several Chrome Flaws That Can Be Exploited via Malicious Extensions
2021-08-04 11:08

A Chrome 92 update released this week by Google patches 10 vulnerabilities, including several high-severity flaws that earned researchers tens of thousands of dollars in bug bounties.

Google described the issue as a heap buffer overflow in Bookmarks.

These were not the first extension-related Chrome vulnerabilities reported by Erceg to Google.

Another high-severity vulnerability for which Google paid out $20,000 is CVE-2021-30591, a use-after-free bug in the File System API. This issue was discovered by researcher SorryMybad from Kunlun Lab.

It's worth noting that Google pays out up to $20,000 for Chrome sandbox escape vulnerabilities described in a high-quality report.

Google this year patched more than half a dozen actively exploited zero-day flaws.


News URL

http://feedproxy.google.com/~r/securityweek/~3/PO9ce10AcPA/google-patches-several-chrome-flaws-can-be-exploited-malicious-extensions

Related Vulnerability

DATE CVE VULNERABILITY TITLE RISK
2021-08-26 CVE-2021-30591 Use After Free vulnerability in multiple products
Use after free in File System API in Google Chrome prior to 92.0.4515.131 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
network
low complexity
google fedoraproject CWE-416
8.8

Related vendor

VENDOR LAST 12M #/PRODUCTS LOW MEDIUM HIGH CRITICAL TOTAL VULNS
Google 141 996 4899 2857 1622 10374