Google Chrome browser 110.0.5481.177Universe. 178 released, Qianxin Group reported that the "intermediate" vulnerability received a reward of $11000
Thanks to CTOnews.com netizen Sentinel for the clue delivery! CTOnews.com, February 23 (Xinhua)-- Google today released an update to Chrome 110.0.5481.177amp .178 for macOS, Linux and Windows platforms. This update mainly fixes 10 vulnerabilities, including a "critical" level of security vulnerability.
According to Google's official update log, users of the macOS and Linux platforms will upgrade to the Chrome 110.0.5481.177 update, while the Windows platform will upgrade to the Chrome 110.0.5481.177amp .178 update.
Only eight vulnerabilities were listed in the official update log, of which CVE-2023-0933 was the Zhiyi Zhang report of Qianxin Group's Codesafe team and received a reward of $11000 (CTOnews.com Note: currently about 75900 yuan). The relevant fixes attached to CTOnews.com are as follows:
[$TBD] [1415366] "critical" CVE-2023-0941: there is a Use after free problem in Prompts.
[$31000] [1414738] "High risk" CVE-2023-0927: there is a Use after free problem in Web Payments API.
[$13000] [1309035] "High risk" CVE-2023-0928: there is a Use after free problem in SwiftShader.
[$10000] [1399742] "High risk" CVE-2023-0929: there is a Use after free problem in Vulkan.
[$10000] [1410766] "High risk" CVE-2023-0930: heap buffer overflow in video.
[$3000] [1407701] "High risk" CVE-2023-0931: there is a Use after free problem in the video.
[$TBD] [1413005] "High risk" CVE-2023-0932: Use after free problems exist in WebRTC.
[$11000] [1404864] Integer overflow in "intermediate" CVE-2023-0933:PDF.