Google Fixes 28 Security Flaws in Chrome 33

Google Chrome 33 is out, and the new version of the browser includes fixes for 28 security vulnerabilities, including a number of high-severity bugs. The company paid out more than $13,000 in rewards to researchers who reported vulnerabilities that were fixed in this release.

One of the high-priority vulnerabilities Google patched in Chrome 33 is an issue with the sandbox in Window. The company also patched a use-after-free vulnerability in the layout of Chrome. Here’s the full list of the bugs discovered by external security researchers fixed in Chrome 33:

[$2000][334897High CVE-2013-6652: Issue with relative paths in Windows sandbox named pipe policy. Credit to tyranid.
[$1000][331790High CVE-2013-6653: Use-after-free related to web contents. Credit to Khalil Zhani.
[$3000][333176High CVE-2013-6654: Bad cast in SVG. Credit to TheShow3511.
[$3000][293534High CVE-2013-6655: Use-after-free in layout. Credit to cloudfuzzer.
[$500][331725High CVE-2013-6656: Information leak in XSS auditor. Credit to NeexEmil.
[$1000][331060Medium CVE-2013-6657: Information leak in XSS auditor. Credit to NeexEmil.
[$2000][322891Medium CVE-2013-6658: Use-after-free in layout. Credit to cloudfuzzer.
[$1000][306959Medium CVE-2013-6659: Issue with certificates validation in TLS handshake. Credit to Antoine Delignat-Lavaud and Karthikeyan Bhargavan from Prosecco, Inria Paris.

[332579Low CVE-2013-6660: Information leak in drag and drop. Credit to bishopjeffreys.

In addition to these vulnerabilities, Google also fixed more than a dozen bugs that were discovered by the company’s internal security team. That group of bugs includes 15 high-severity flaws and two medium-level vulnerabilities.

Suggested articles

We use cookies to make your experience of our websites better. By using and further navigating this website you accept this. Detailed information about the use of cookies on this website is available by clicking on more information.

ACCEPT AND CLOSE