Google has released Chrome version 104.0.5112.101, which fixes 10 vulnerabilities, including a critical vulnerability (CVE-2022-2852) that allows bypassing all levels of browser protection and executing code in the system outside of the sandbox environment. Details have not yet been disclosed, but it is known that the critical vulnerability is related to a use-after-free issue in the FedCM API (Federated Credential Management), which allows the creation of unified identification services that ensure privacy and operate without cross-site tracking mechanisms, such as third-party cookie handling.
Other fixed vulnerabilities include issues with use-after-free in the Swiftshader rendering system, the Blink engine, OS Shell, linking Chrome sign-in to Google services, and the ANGLE layer. Additionally, the update addresses buffer overflows in the download management code, shortcomings in the Extensions API, and incorrect input validation in the application invocation mechanism from web pages (Intents).
Source: opennet.ru
