Google Rolls Out 3 Critical Chrome Memory Fixes In 48 Hour Period

If you’re one of many 3.5 billion individuals utilizing Google’s Chrome internet browser, then buffer overflow and use-after-free are among the many safety points you doubtless have by no means heard of. Fortunately, the Google safety staff is aware of all about such reminiscence vulnerabilities and, inside simply 48 hours, has launched software updates to repair three such essential flaws.

The excellent news is that CVE-2026-76034, CVE-2026-76036 and CVE-2026-76017 have all been rendered innocent so long as you will have restarted your browser after the automated replace course of. Much less so is the truth that extra vulnerabilities are being found by bounty hunters assisted by AI instruments, leaving Google combating a battle to patch them earlier than much less conscientious hackers discover them and put them to prison use.

Google Has Patched Crucial Chrome CVE-2026-76034, CVE-2026-76036 And CVE-2026-76017 Reminiscence Points

In an August 18 announcement, Google Chrome’s Srinivas Sista confirmed {that a} whole of 15 vulnerabilities had been addressed by the replace, bringing Chrome to model 151.0.7922.169/.170 for Home windows, Mac and Linux. Of those, two have been critical-rated and each have been of the buffer overflow selection. Inside 48 hours, Sista was again with a new announcement: Chrome had now been up to date to model 151.0.7922.173/.174 resulting from seven further vulnerabilities, together with one essential use-after-free safety difficulty. It is a repeat of the two-updates-in-two-days occasion that I reported on July 18, nearly precisely a month in the past. On the time, I wrote how Google’s technical program supervisor, Daniel Yip, had confirmed that essential reminiscence vulnerabilities have been included.

The newest essential Chrome browser vulnerabilities to be patched have been as follows:

  • CVE-2026-76034 was a buffer overflow within the WebGL internet graphics part.
  • CVE-2026-76036 was one other buffer overflow, however this time inside the Daybreak open-source graphics library utilized by Chrome.
  • CVE-2026-76017 was a use-after-free difficulty with Google’s proprietary Chromoting distant desktop protocol part.

All three vulnerabilities have been discovered by Google’s personal vulnerability safety staff.

To grasp these points, let’s examine use-after-free and buffer overflow vulnerabilities. Each are essential reminiscence safety points, differing primarily by means of location. A use-after-free vulnerability happens when a program accesses reminiscence after it is discarded; heap buffer overflows occur when extra information is written than allotted. The top outcomes are sometimes related, together with distant code execution, privilege escalation, information leaks and crashes. Which is why it’s essential to make sure that the Google Chrome replace is downloaded and activated promptly.

It is best to have already acquired the automated safety replace from Google to your Chrome software. If you’re requested to restart your browser, it is a giveaway that it has. If not, you should utilize the three-dot Chrome menu to manually begin the replace search, obtain and set up course of.

Source link

Leave a Reply

Your email address will not be published. Required fields are marked *