==================================================================== CERT-Renater Note d'Information No. 2018/VULN397 _____________________________________________________________________ DATE : 22/11/2018 HARDWARE PLATFORM(S): / OPERATING SYSTEM(S): Systems running Google Chrome, Chrome OS versions prior to 70.0.3538.110. ===================================================================== https://chromereleases.googleblog.com/2018/11/stable-channel-update-for-desktop_19.html https://chromereleases.googleblog.com/2018/11/chrome-for-android-update.html https://chromereleases.googleblog.com/2018/11/stable-channel-update-for-chrome-os.html _____________________________________________________________________ Stable Channel Update for Desktop Monday, November 19, 2018 The stable channel has been updated to 70.0.3538.110 for Windows, Mac, and Linux, which will roll out over the coming days/weeks. A list of all changes is available in the log. Interested in switching release channels? Find out how. If you find a new issue, please let us know by filing a bug. The community help forum is also a great place to reach out for help or learn about common issues. Security Fixes and Rewards Note: Access to bug details and links may be kept restricted until a majority of users are updated with a fix. We will also retain restrictions if the bug exists in a third party library that other projects similarly depend on, but haven’t yet fixed. This update includes 1 security fix. Please see the Chrome Security Page for more information. [905336] High CVE-2018-17479: Use-after-free in GPU. We would also like to thank all security researchers that worked with us during the development cycle to prevent security bugs from ever reaching the stable channel. Many of our security bugs are detected using AddressSanitizer, MemorySanitizer, UndefinedBehaviorSanitizer, Control Flow Integrity, libFuzzer, or AFL. Abdul Syed Google Chrome ______________________________________________________________ Chrome for Android Update Monday, November 19, 2018 Good news, everyone! Chrome 70 (70.0.3538.110) for Android has been released and will be available on Google Play over the course of the next few weeks. This release includes stability and performance improvements. A list of the changes in this build is available in the Git log. If you find a new issue, please let us know by filing a bug. More information about Chrome for Android is available on the Chrome site. Ben Mason Google Chrome _____________________________________________________________________ Stable Channel Update for Chrome OS Monday, November 19, 2018 The Stable channel has been updated to 70.0.3538.110 (Platform version: 11021.81.0) for most Chrome OS devices. This build contains a number of bug fixes and security updates. Systems will be receiving updates over the next several days. Security Fixes and Rewards Note: Access to bug details and links may be kept restricted until a majority of users are updated with a fix. We will also retain restrictions if the bug exists in a third party library that other projects similarly depend on, but haven’t yet fixed. This update includes 1 security fix. Please see the Chrome Security Page for more information. [905336] High CVE-2018-17479: Use-after-free in GPU. If you find new issues, please let us know by visiting our forum or filing a bug. Interested in switching channels? Find out how. You can submit feedback using ‘Report an issue...’ in the Chrome menu (3 vertical dots in the upper right corner of the browser). Geo Hsu ========================================================= + CERT-RENATER | tel : 01-53-94-20-44 + + 23/25 Rue Daviel | fax : 01-53-94-20-41 + + 75013 Paris | email:cert@support.renater.fr + =========================================================