Web browsers: Google Chrome and Microsoft Edge 104 close security holes
Summary
With Chrome 104 in August 2022, Google closed 27 security holes, at least seven of them high-risk; one earned its discoverer a bounty of 15,000 US dollars. Microsoft followed with Edge 104 and additionally fixed three Edge-specific bugs, including a critical sandbox escape (CVE-2022-33649, CVSS 9.6). Also new were Media Queries Level 4 and Web Bundles for faster loading.
Ideas
- Chromium holes affect all browsers based on it.
- Google withholds details until most users have updated.
- The size of the bounty indicates the severity of a hole.
- On Linux the update comes via the package manager, not via the browser.
Insights
- A browser monoculture bundles risks across vendor boundaries.
- Automatic updates are the most important protection, because browsers constantly acquire new holes.
Facts
- The Chrome version was 104.0.5112.79 for Mac and Linux.
- Edge 104 appeared as version 104.0.1293.47.
References
Critique
- The report mixes security updates and new features, which dilutes the urgency.
Recommendations
- Restart browsers after updates so that the new version is actually running.
- On Linux systems, check that browser packages come from maintained sources and are updated automatically.
Links to the original source and the Web Archive open in a new tab.