Lucene search

K
chromeHttps://chromereleases.googleblog.comGCSA-5747166286807692363
HistoryMar 05, 2024 - 12:00 a.m.

Stable Channel Update for ChromeOS / ChromeOS Flex

2024-03-0500:00:00
https://chromereleases.googleblog.com
chromereleases.googleblog.com
41
chromeos
stable channel
bug fixes
security updates
critical vulnerabilities
high vulnerabilities
out of bounds memory access
use after free
recovery images
vulnerability rewards program
chrome browser
lts channel
exploitation
known vulnerabilities

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

7.8

Confidence

High

EPSS

0.584

Percentile

97.8%

The Stable channel is being updated to 122.0.6045.214 (Platform version: 15753.38.0) for most ChromeOS devices and will be rolled out over the coming days. This build contains a number of bug fixes and security updates.

If you find new issues, please let us know one of the following ways:

Interested in switching channels? Find out how.

Cole Brown,

Google ChromeOS

Security Fixes and Rewards


ChromeOS Vulnerability Rewards Program Reported Bug Fixes:


N/A


Security Fixes Included:


Critical Fixes CVE-2024-0204 in kiosk mode on ChromeOS

High Fixes a regression in the recovery keyset for select models that allows older recovery images with known vulnerability

Medium Fixes CVE-2024-1086 in Linux Kernel

Medium Fixes CVE-2023-5427 in Linux Kernel

Medium Fixes CVE-2023-28746 in impacted Intel processors

**

**

Chrome Browser Security Fixes:


[$12000][325893559] High CVE-2024-2173: Out of bounds memory access in V8. Reported by 5fceb6172bbf7e2c5a948183b53565b9 on 2024-02-19

[$7000][325866363] High CVE-2024-2174: Inappropriate implementation in V8. Reported by 5f46f4ee2e17957ba7b39897fb376be8 on 2024-02-19

[$6000][325936438] High CVE-2024-2176: Use after free in FedCM. Reported by Anonymous on 2024-02-20

**

**

Users who are pinned to a specific release of ChromeOS will not receive these security fixes or any other security fixes. We recommend updating to the latest version of Stable to ensure you are protected against exploitation of known vulnerabilities.

To see fixes included in the Long Term Stable channel, see the release notes.

Affected configurations

Vulners
Node
googlechrome_osRange<122.0.6045.214
VendorProductVersionCPE
googlechrome_os*cpe:2.3:o:google:chrome_os:*:*:*:*:*:*:*:*

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

7.8

Confidence

High

EPSS

0.584

Percentile

97.8%