Advisory

Google patches Chrome critical and high severity vulnerabilities

Take action: Once more, Chrome and Chromium based browsers (Brave, Edge, Opera) need an update. Fortunately, the update is very easy, and you get all your tabs back after a restart of the browser. Don't delay, someone will find a way to exploit them soon enough.


Learn More

Google has released a Stable Channel update for Chrome Desktop, moving to version 127.0.6533.88/89 for Windows and Mac, and 127.0.6533.88 for Linux. This update, set to roll out over the next few days, includes several security fixes.

The update addresses three significant security vulnerabilities:

  1. CVE-2024-6990 (CVSS score 9.8): a flaw due to uninitialized use in Dawn
  2. CVE-2024-7255 (CVSS score 9.8): an out-of-bounds read issue in WebTransport,
  3. CVE-2024-7256 (CVSS score 9.8): an insufficient data validation issue in Dawn,

Fixed versions

  • Version: 127.0.6533.88/89 for Windows, Mac; 127.0.6533.88 for Linux
  • Release Date: July 30, 2024

Details on these vulnerabilities are restricted until a majority of users have updated to the latest version to prevent exploitation. Further information is available on the Chrome Security Page.

Google patches Chrome critical and high severity vulnerabilities