After 1 month of the previous chrome version 99, Google has announced the release of chrome version 100. Google also said that this version has an extended stable channel for Mac and Windows.
The new chrome 100.0.4896.60 has a lot of bugs fixed from the previous versions. Features about the new version of both chrome and chromium are yet to be announced by Google.
This new version of chrome has nearly 28 security issues updated. Google also stated, “Access to bug details and links may be kept restricted until a majority of users are updated with a fix. We will also retain restrictions if the bug exists in a third party library that other projects similarly depend on, but haven’t yet fixed”.
The all-new Chrome 100 for the Stable desktop channel has been released by Google on March 29th, 2022. The new Google Chrome 100 (100.0.4896.60) includes several new additions like:-
- A new logo
- Security improvements
- Development features
- Many more
Many external security researchers have contributed to these security issues. The bugs and their rewards are:
Bounty | Report ID | Severity | CVEs | Description | Reported By |
$ 7000 | 1292261 | High | CVE-2022-1125 | Use after free in Portals | Khalil Zhani on 2022-01-29 |
$ 5000 | 1291891 | High | CVE-2022-1127 | Use after free in QR Code Generator | anonymous on 2022-01-28 |
$ 5000 | 1301920 | High | CVE-2022-1128 | Inappropriate implementation in Web Share API | Abdel Adim (@smaury92) Oisfi of Shielder on 2022-03-01 |
$ 3000 | 1300253 | High | CVE-2022-1129 | Inappropriate implementation in Full Screen Mode | Irvan Kurniawan (sourc7) on 2022-02-24 |
$ 1000 | 1142269 | High | CVE-2022-1130 | Insufficient validation of untrusted input in WebOTP | Sergey Toshin of Oversecurity Inc on 2020-10-25 |
$NA | 1297404 | High | CVE-2022-1131 | Use after free in Cast UI | Abdulrahman Alqabandi, Microsoft Browser Vulnerability Research on 2022-02-15 |
$TBD | 1303410 | High | CVE-2022-1132 | Inappropriate implementation in Virtual Keyboard | Andr Ess on 2022-03-07 |
$TBD | 1305776 | High | CVE-2022-1133 | Use after free in WebRTC | Anonymous on 2022-03-13 |
$TBD | 1308360 | High | CVE-2022-1134 | Type Confusion in V8 | Man Yue Mo of GitHub Security Lab on 2022-03-21 |
$ 16000 | 1285601 | Medium | CVE-2022-1135 | Use after free in Shopping Cart | Wei Yuan of MoyunSec VLab on 2022-01-09 |
$ 7000 | 1280205 | Medium | CVE-2022-1136 | Use after free in Tab Strip | Krace on 2021-12-15 |
$ 5000 | 1289846 | Medium | CVE-2022-1137 | Inappropriate implementation in Extensions | Thomas Orlita on 2022-01-22 |
$ 2000 | 1246188 | Medium | CVE-2022-1138 | Inappropriate implementation in Web Cursor | Alesandro Ortiz on 2021-09-03 |
$TBD | 1268541 | Medium | CVE-2022-1139 | Inappropriate implementation in Background Fetch API | Maurice Dauer on 2021-11-10 |
$TBD | 1303253 | Medium | CVE-2022-1141 | Use after free in File Manager | raven at KunLun lab on 2022-03-05 |
$TBD | 1303613 | Medium | CVE-2022-1142 | Heap buffer overflow in WebUI | Leecraso and Guang Gong of 360 Alpha Lab on 2022-03-07 |
$TBD | 1303615 | Medium | CVE-2022-1143 | Heap buffer overflow in WebUI | Leecraso and Guang Gong of 360 Alpha Lab on 2022-03-07 |
$TBD | 1304145 | Medium | CVE-2022-1144 | Use after free in WebUI | Leecraso and Guang Gong of 360 Alpha Lab on 2022-03-08 |
$TBD | 1304545 | Medium | CVE-2022-1145 | Use after free in Extensions | Yakun Zhang of Baidu Security on 2022-03-09 |
$TBD | 1290150 | Low | CVE-2022-1146 | Inappropriate implementation in Resource Timing | Sohom Datta on 2022-01-23 |
Most of the security bugs were
- AddressSanitizer
- MemorySanitizer
- UndefinedBehaviorSanitizer
- Control Flow Integrity
- libFuzzer
- AFL.
Want to upgrade your old Chrome, then you have to follow a few simple steps that we have mentioned below:-
- First of all, you have to go to Settings.
- Then click on the Help option.
- After that, you have to select the About Google Chrome option.
- That’s it, now your browser will automatically check for the new update and install it.
You can follow us on Linkedin, Twitter, Facebook for daily Cybersecurity and hacking news updates.