An out of bounds read flaw was found in the V8 component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=907714
External References:
https://chromereleases.googleblog.com/2018/12/stable-channel-update-for-desktop.html
An incorrect security ui flaw was found in the Blink component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=606104
External References:
https://chromereleases.googleblog.com/2018/12/stable-channel-update-for-desktop.html
An inappropriate implementation flaw was found in the Navigation component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=850824
External References:
https://chromereleases.googleblog.com/2018/12/stable-channel-update-for-desktop.html
An use after free flaw was found in the MediaRecorder component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=896736
External References:
https://chromereleases.googleblog.com/2018/12/stable-channel-update-for-desktop.html
A heap buffer overflow flaw was found in the Blink component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=901030
External References:
https://chromereleases.googleblog.com/2018/12/stable-channel-update-for-desktop.html
An use after free flaw was found in the Skia component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=882423
External References:
https://chromereleases.googleblog.com/2018/12/stable-channel-update-for-desktop.html
An use after free flaw was found in the Blink component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=886753
External References:
https://chromereleases.googleblog.com/2018/12/stable-channel-update-for-desktop.html
An use after free flaw was found in the PDFium component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=898531
External References:
https://chromereleases.googleblog.com/2018/12/stable-channel-update-for-desktop.html
A heap buffer overflow flaw was found in the Canvas component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=890576
External References:
https://chromereleases.googleblog.com/2018/12/stable-channel-update-for-desktop.html
An use after free flaw was found in the WebAudio component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=891187
External References:
https://chromereleases.googleblog.com/2018/12/stable-channel-update-for-desktop.html
An use after frees flaw was found in the PDFium component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=901654
External References:
https://chromereleases.googleblog.com/2018/12/stable-channel-update-for-desktop.html
Object lifecycle issue in Chrome Custom Tab in Google Chrome prior to 65.0.3325.146 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
An url spoof flaw was found in the Omnibox component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=882078
External References:
https://chromereleases.googleblog.com/2018/10/stable-channel-update-for-desktop.html
A heap buffer overflow flaw was found in the PDFium component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=880675
External References:
https://chromereleases.googleblog.com/2018/10/stable-channel-update-for-desktop.html
An url spoof flaw was found in the Omnibox component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=887273
External References:
https://chromereleases.googleblog.com/2018/10/stable-channel-update-for-desktop.html
A sandbox escape flaw was found in the AppCache component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=888926
External References:
https://chromereleases.googleblog.com/2018/10/stable-channel-update-for-desktop.html
A double-eviction in the Incognito mode cache that lead to a user-after-free in Networking Disk Cache in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to execute arbitrary code via a crafted HTML page.
An use after free flaw was found in the Disk Cache component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=826626
External References:
https://chromereleases.googleblog.com/2018/04/stable-channel-update-for-desktop.html
An iterator-invalidation bug in PDFium in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted PDF file.
A nullptr dereference in WebAssembly in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page.
A heap buffer overflow flaw was found in the Skia component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=820913
External References:
https://chromereleases.googleblog.com/2018/04/stable-channel-update-for-desktop.html
An url spoof flaw was found in the Omnibox component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=820068
External References:
https://chromereleases.googleblog.com/2018/04/stable-channel-update-for-desktop.html
An integer overflow flaw was found in the WebAssembly component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=819869
External References:
https://chromereleases.googleblog.com/2018/04/stable-channel-update-for-desktop.html
A xss flaw was found in the interstitials component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=797525
External References:
https://chromereleases.googleblog.com/2018/03/stable-channel-update-for-desktop.html
Failure to apply Mark-of-the-Web in Downloads in Google Chrome prior to 65.0.3325.146 allowed a remote attacker to bypass OS level controls via a crafted HTML page.
An incorrect handling of url fragment identifiers flaw was found in the Blink component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=758523
External References:
https://chromereleases.googleblog.com/2018/03/stable-channel-update-for-desktop.html
Incorrect handling of specified filenames in file downloads in Google Chrome prior to 65.0.3325.146 allowed a remote attacker to leak cross-origin data via a crafted HTML page and user interaction.
An integer overflow flaw was found in the PDFium component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=791048
External References:
https://chromereleases.googleblog.com/2018/03/stable-channel-update-for-desktop.html
A heap buffer overflow in WebGL in Google Chrome prior to 65.0.3325.146 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page.
A stack buffer overflow flaw was found in the Skia component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=799918
External References:
https://chromereleases.googleblog.com/2018/03/stable-channel-update-for-desktop.html