Eliminates important out-of-bounds read in HTTP and SVG

Nov 12, 2013 17:17 GMT  ·  By

Today, Google has rolled out a new major version for the stable channel of Chrome browser, incrementing the build number to 31.0.1650.48. The fresh revision is available for Windows, Mac, Linux and Chrome Frame and the most significant changes are security related.

The developer informs that the current update includes a number of 25 fixes. Among the most significant of them, there are use after free vulnerabilities relating to speech input and media elements, as well as “id” attribute string and in DOM ranges.

Also marked “high” were two out-of-bounds read vulnerabilities in HTTP and SVG.

For the contribution of external researchers, Google spent a total of $11,000/ €8,179, the highest reward ($4,000 / €2,974) being given to “skylined” for reporting the out-of-bounds read in HTTP.

An additional $2,000 / €1,488 were awarded to researchers that worked with the Google Chrome team during the development cycle of this version to quash a set of bugs before pushing the update.

Download Google Chrome for Windows
Download Google Chrome for Mac
Download Google Chrome for Linux