Google Chrome Security Update – 20 November 2024

 Google has released an updated Chrome version 131.0.6778.85/.86 for Windows, and Mac and 131.0.6778.85 for Linux

The addressed vulnerability could allow the remote attacker to gain access to the affected system, which could be caused by potentially exploiting heap corruption via a crafted HTML page.

Google Chrome Heap Exploitation Vulnerability (CVE-2024-11395):

  • CVSS: 8.8
  • Attack Vector: Network
  • Attack Complexity: Low
  • Privileges Required: None
  • User Interaction: Required
  • Consequences: Gain Access
Vulnerabilities

 CVE-2024-11395

Mitigations

The enterprise should deploy this patch as soon as the testing phase is completed.

Google Chrome Security Update

References