(2011.02.08)
The stable channel has been updated to 9.0.597.94 for all platforms. This release contains an updated version of Flash player (10.2), along with the following security fixes.
Security fixes and rewards:
Please see the Chromium security page for more detail. Note that the referenced bugs may be kept private until a majority of our users are up to date with the fix.
This release incorporates a new version of Flash (10.2), which is a security update.
* [67234] High Stale pointer in animation event handling. Credit to Rik Cabanier.
* [$1000] [68120] High Use-after-free in SVG font faces. Credit to miaubiz.
* [$1000] [69556] High Stale pointer with anonymous block handling. Credit to Martin Barbella.
* [69970] Medium Out-of-bounds read in plug-in handling. Credit to Bill Budge of Google.
* [$1000] [70456] Medium Possible failure to terminate process on out-of-memory condition. Credit to David Warren of CERT/CC.
If you find new issues, please let us know by filing a bug. Want to change to another Chrome release channel? Find out how.
-DOWNLOAD-
Google Chrome 9.0.597.94 (Windows) / Google Chrome 9.0.597.94 (Mac) / Google Chrome 9.0.597.94 (Linux)
Showing posts with label chrome. Show all posts
Showing posts with label chrome. Show all posts
Wednesday, February 9, 2011
Friday, February 4, 2011
Google Chrome 9.0.597.84
(2011.02.03)
The stable channel has been updated to 9.0.597.84 for all platforms. Details about the features included in this release can be found on the Google Chrome Blog, in addition this release contains the following security fixes.
Security fixes and rewards:
Please see the Chromium security page for more detail. Note that the referenced bugs may be kept private until a majority of our users are up to date with the fix.
Special thanks to the
community, for playing so much of the game “Z-Type” that they uncovered a Chromium audio bug -- see below!
* [Mac only] [42989] Low Minor sandbox leak via stat(). Credit to Daniel Cheng of the Chromium development community.
* [$1000] [55831] High Use-after-free in image loading. Credit to Aki Helin of OUSPG.
* [59081] Low Apply some restrictions to cross-origin drag + drop. Credit to Google Chrome Security Team (SkyLined) and the Google Security Team (Michal Zalewski, David Bloom).
* [62791] Low Browser crash with extension with missing key. Credit to Brian Kirchoff.
* [$1000] [64051] High Crashing when printing in PDF event handler. Credit to Aki Helin of OUSPG.
* [65669] Low Handle merging of autofill profiles more gracefully. Credit to Google Chrome Security Team (Inferno).
* [Mac only] [66931] Low Work around a crash in the Mac OS 10.5 SSL libraries. Credit to Dan Morrison.
* [68244] Low Browser crash with bad volume setting. Credit to Matthew Heidermann.
* [69195] Critical Race condition in audio handling. Credit to the gamers of Reddit!
In addition, we would like to thank Aki Helin, Sergey Glazunov, Ben Hawkes of the Google Security Team, Benoit Jacob, Simon Fraser and miaubiz for reporting bugs to us during the development cycle, so that they never affected the stable channel. Various rewards were issued for this help.
If you find new issues, please let us know by filing a bug. Want to change to another Chrome release channel? Find out how.
-DOWNLOAD-
Google Chrome 9.0.597.84 (Windows) / Google Chrome 9.0.597.84 (Mac) / Google Chrome 9.0.597.84 (Linux)
The stable channel has been updated to 9.0.597.84 for all platforms. Details about the features included in this release can be found on the Google Chrome Blog, in addition this release contains the following security fixes.
Security fixes and rewards:
Please see the Chromium security page for more detail. Note that the referenced bugs may be kept private until a majority of our users are up to date with the fix.
Special thanks to the
* [Mac only] [42989] Low Minor sandbox leak via stat(). Credit to Daniel Cheng of the Chromium development community.
* [$1000] [55831] High Use-after-free in image loading. Credit to Aki Helin of OUSPG.
* [59081] Low Apply some restrictions to cross-origin drag + drop. Credit to Google Chrome Security Team (SkyLined) and the Google Security Team (Michal Zalewski, David Bloom).
* [62791] Low Browser crash with extension with missing key. Credit to Brian Kirchoff.
* [$1000] [64051] High Crashing when printing in PDF event handler. Credit to Aki Helin of OUSPG.
* [65669] Low Handle merging of autofill profiles more gracefully. Credit to Google Chrome Security Team (Inferno).
* [Mac only] [66931] Low Work around a crash in the Mac OS 10.5 SSL libraries. Credit to Dan Morrison.
* [68244] Low Browser crash with bad volume setting. Credit to Matthew Heidermann.
* [69195] Critical Race condition in audio handling. Credit to the gamers of Reddit!
In addition, we would like to thank Aki Helin, Sergey Glazunov, Ben Hawkes of the Google Security Team, Benoit Jacob, Simon Fraser and miaubiz for reporting bugs to us during the development cycle, so that they never affected the stable channel. Various rewards were issued for this help.
If you find new issues, please let us know by filing a bug. Want to change to another Chrome release channel? Find out how.
-DOWNLOAD-
Google Chrome 9.0.597.84 (Windows) / Google Chrome 9.0.597.84 (Mac) / Google Chrome 9.0.597.84 (Linux)
Tags:
chrome,
google,
web browser
Thursday, January 13, 2011
Google Chrome 8.0.552.237
(2011.01.12)
Chrome on stable channel has been updated to 8.0.552.237 for all platforms. Chrome OS has also been updated, to 8.0.552.334. These releases contain the security fixes listed below.
Security fixes and rewards:
Please see the Chromium security page for more detail. Note that the referenced bugs may be kept private until a majority of our users are up to date with the fix.
We’re delighted to offer our first “elite” $3133.7 Chromium Security Reward to Sergey Glazunov. Critical bugs are harder to come by in Chrome, but Sergey has done it. Sergey also collects a $1337 reward and several other rewards at the same time, so congratulations Sergey!
Also of note is a clarification on our default charity policy. Some researchers are unable to accept rewards, or even provide a suggestion for a charity. In such cases, it feels like a shame to lose a charitable contribution so we will default reward money to the Red Cross.
* [58053] Medium Browser crash in extensions notification handling. Credit to Eric Roman of the Chromium development community.
* [$1337] [65764] High Bad pointer handling in node iteration. Credit to Sergey Glazunov.
* [66334] High Crashes when printing multi-page PDFs. Credit to Google Chrome Security Team (Chris Evans).
* [$1000] [66560] High Stale pointer with CSS + canvas. Credit to Sergey Glazunov.
* [$500] [66748] High Stale pointer with CSS + cursors. Credit to Jan Tošovský.
* [67100] High Use after free in PDF page handling. Credit to Google Chrome Security Team (Chris Evans).
* [$1000] [67208] High Stack corruption after PDF out-of-memory condition. Credit to Jared Allar of CERT.
* [$1000] [67303] High Bad memory access with mismatched video frame sizes. Credit to Aki Helin of OUSPG; plus independent discovery by Google Chrome Security Team (SkyLined) and David Warren of CERT.
* [$500] [67363] High Stale pointer with SVG use element. Credited anonymously; plus indepdent discovery by miaubiz.
* [$1000] [67393] Medium Uninitialized pointer in the browser triggered by rogue extension. Credit to kuzzcc.
* [$1000] [68115] High Vorbis decoder buffer overflows. Credit to David Warren of CERT.
* [$1000] [68170] High Buffer overflow in PDF shading. Credit to Aki Helin of OUSPG.
* [$1000] [68178] High Bad cast in anchor handling. Credit to Sergey Glazunov.
* [$1000] [68181] High Bad cast in video handling. Credit to Sergey Glazunov.
* [$1000] [68439] High Stale rendering node after DOM node removal. Credit to Martin Barbella; plus independent discovery by Google Chrome Security Team (SkyLined).
* [$3133.7] [68666] Critical Stale pointer in speech handling. Credit to Sergey Glazunov.
Full details about the Chrome changes are available in the SVN revision log. If you find new issues, please let us know by filing a bug. Want to change to another Chrome release channel? Find out how.
-DOWNLOAD-
Google Chrome 8.0.552.237 (Windows) / Google Chrome 8.0.552.237 (Mac) / Google Chrome 8.0.552.237 (Linux)
Chrome on stable channel has been updated to 8.0.552.237 for all platforms. Chrome OS has also been updated, to 8.0.552.334. These releases contain the security fixes listed below.
Security fixes and rewards:
Please see the Chromium security page for more detail. Note that the referenced bugs may be kept private until a majority of our users are up to date with the fix.
We’re delighted to offer our first “elite” $3133.7 Chromium Security Reward to Sergey Glazunov. Critical bugs are harder to come by in Chrome, but Sergey has done it. Sergey also collects a $1337 reward and several other rewards at the same time, so congratulations Sergey!
Also of note is a clarification on our default charity policy. Some researchers are unable to accept rewards, or even provide a suggestion for a charity. In such cases, it feels like a shame to lose a charitable contribution so we will default reward money to the Red Cross.
* [58053] Medium Browser crash in extensions notification handling. Credit to Eric Roman of the Chromium development community.
* [$1337] [65764] High Bad pointer handling in node iteration. Credit to Sergey Glazunov.
* [66334] High Crashes when printing multi-page PDFs. Credit to Google Chrome Security Team (Chris Evans).
* [$1000] [66560] High Stale pointer with CSS + canvas. Credit to Sergey Glazunov.
* [$500] [66748] High Stale pointer with CSS + cursors. Credit to Jan Tošovský.
* [67100] High Use after free in PDF page handling. Credit to Google Chrome Security Team (Chris Evans).
* [$1000] [67208] High Stack corruption after PDF out-of-memory condition. Credit to Jared Allar of CERT.
* [$1000] [67303] High Bad memory access with mismatched video frame sizes. Credit to Aki Helin of OUSPG; plus independent discovery by Google Chrome Security Team (SkyLined) and David Warren of CERT.
* [$500] [67363] High Stale pointer with SVG use element. Credited anonymously; plus indepdent discovery by miaubiz.
* [$1000] [67393] Medium Uninitialized pointer in the browser triggered by rogue extension. Credit to kuzzcc.
* [$1000] [68115] High Vorbis decoder buffer overflows. Credit to David Warren of CERT.
* [$1000] [68170] High Buffer overflow in PDF shading. Credit to Aki Helin of OUSPG.
* [$1000] [68178] High Bad cast in anchor handling. Credit to Sergey Glazunov.
* [$1000] [68181] High Bad cast in video handling. Credit to Sergey Glazunov.
* [$1000] [68439] High Stale rendering node after DOM node removal. Credit to Martin Barbella; plus independent discovery by Google Chrome Security Team (SkyLined).
* [$3133.7] [68666] Critical Stale pointer in speech handling. Credit to Sergey Glazunov.
Full details about the Chrome changes are available in the SVN revision log. If you find new issues, please let us know by filing a bug. Want to change to another Chrome release channel? Find out how.
-DOWNLOAD-
Google Chrome 8.0.552.237 (Windows) / Google Chrome 8.0.552.237 (Mac) / Google Chrome 8.0.552.237 (Linux)
Tags:
chrome,
google,
web browser
Tuesday, December 14, 2010
Google Chrome 8.0.552.224
(2010.12.13)
The Chrome Stable and Beta channels have been updated to 8.0.552.224 for all platforms. Chrome OS has also been updated to 8.0.552.343. These releases contain the security fixes listed below, along with stability and other improvements.
Security fixes and rewards:
Please see the Chromium security page for more detail. Note that the referenced bugs may be kept private until a majority of our users are up to date with the fix.
* [64-bit Linux only] [56449] High Bad validation for message deserialization on 64-bit builds. Credit to Lei Zhang of the Chromium development community.
* [60761] Medium Bad extension can cause browser crash in tab handling. Credit to kuzzcc.
* [63529] Low Browser crash with NULL pointer in web worker handling. Credit to Nathan Weizenbaum of Google.
* [$1000] [63866] Medium Out-of-bounds read in CSS parsing. Credit to Chris Rohlf.
* [$1000] [64959] High Stale pointers in cursor handling. Credit to Sławomir Błażek and Sergey Glazunov.
Full details about the Chrome changes are available in the SVN revision log. If you find new issues, please let us know by filing a bug. Want to change to another Chrome release channel? Find out how.
-DOWNLOAD-
Google Chrome 8.0.552.224 (Windows) / Google Chrome 8.0.552.224 (Mac) / Google Chrome 8.0.552.224 (Linux)
The Chrome Stable and Beta channels have been updated to 8.0.552.224 for all platforms. Chrome OS has also been updated to 8.0.552.343. These releases contain the security fixes listed below, along with stability and other improvements.
Security fixes and rewards:
Please see the Chromium security page for more detail. Note that the referenced bugs may be kept private until a majority of our users are up to date with the fix.
* [64-bit Linux only] [56449] High Bad validation for message deserialization on 64-bit builds. Credit to Lei Zhang of the Chromium development community.
* [60761] Medium Bad extension can cause browser crash in tab handling. Credit to kuzzcc.
* [63529] Low Browser crash with NULL pointer in web worker handling. Credit to Nathan Weizenbaum of Google.
* [$1000] [63866] Medium Out-of-bounds read in CSS parsing. Credit to Chris Rohlf.
* [$1000] [64959] High Stale pointers in cursor handling. Credit to Sławomir Błażek and Sergey Glazunov.
Full details about the Chrome changes are available in the SVN revision log. If you find new issues, please let us know by filing a bug. Want to change to another Chrome release channel? Find out how.
-DOWNLOAD-
Google Chrome 8.0.552.224 (Windows) / Google Chrome 8.0.552.224 (Mac) / Google Chrome 8.0.552.224 (Linux)
Tags:
chrome,
google,
web browser
Friday, December 3, 2010
Google Chrome 8.0.552.215
(2010.12.02)
The Chrome team is happy to announce our latest Stable release, 8.0.552.215. In addition to the over 800 bug fixes and stability improvements, Chrome 8 now contains a built in PDF viewer that is secured in Chrome’s sandbox. As always, it also contains our latest security fixes, listed below. This release will also be posted to the Beta Channel.
Security fixes and rewards:
Please see the Chromium security page for more detail. Note that the referenced bugs may be kept private until a majority of our users are up to date with the fix.
* [17655] Low Possible pop-up blocker bypass. Credit to Google Chrome Security Team (SkyLined).
* [55745] Medium Cross-origin video theft with canvas. Credit to Nirankush Panchbhai and Microsoft Vulnerability Research (MSVR).
* [56237] Low Browser crash with HTML5 databases. Credit to Google Chrome Security Team (Inferno).
* [58319] Low Prevent excessive file dialogs, possibly leading to browser crash. Credit to Cezary Tomczak (gosu.pl).
* [$500] [59554] High Use after free in history handling. Credit to Stefan Troger.
* [Linux / Mac] [59817] Medium Make sure the “dangerous file types” list is uptodate with the Windows platforms. Credit to Billy Rios of the Google Security Team.
* [61701] Low Browser crash with HTTP proxy authentication. Credit to Mohammed Bouhlel.
* [61653] Medium Out-of-bounds read regression in WebM video support. Credit to Google Chrome Security Team (Chris Evans), based on earlier testcases from Mozilla and Microsoft (MSVR).
* [$1000] [62127] High Crash due to bad indexing with malformed video. Credit to miaubiz.
* [62168] Medium Possible browser memory corruption via malicious privileged extension. Credit to kuzzcc.
* [$1000] [62401] High Use after free with SVG animations. Credit to Sławomir Błażek.
* [$500] [63051] Medium Use after free in mouse dragging event handling. Credit to kuzzcc.
* [$1000] [63444] High Double free in XPath handling. Credit to Yang Dingning from NCNIPC, Graduate University of Chinese Academy of Sciences.
We would like to offer special thanks -- and a number of rewards -- to Aki Helin of OUSPG for his extensive help with the new PDF feature. We’d also like to extend thanks to Sergey Glazunov and Marc Schoenefeld for finding bugs during the development cycle such that they never reached a stable build.
Full details about the changes are available in the SVN revision log. If you find new issues, please let us know by filing a bug. Want to change to another Chrome release channel? Find out how.
-DOWNLOAD-
Google Chrome 8.0.552.215 (Windows) / Google Chrome 8.0.552.215 (Mac) / Google Chrome 8.0.552.215 (Linux)
The Chrome team is happy to announce our latest Stable release, 8.0.552.215. In addition to the over 800 bug fixes and stability improvements, Chrome 8 now contains a built in PDF viewer that is secured in Chrome’s sandbox. As always, it also contains our latest security fixes, listed below. This release will also be posted to the Beta Channel.
Security fixes and rewards:
Please see the Chromium security page for more detail. Note that the referenced bugs may be kept private until a majority of our users are up to date with the fix.
* [17655] Low Possible pop-up blocker bypass. Credit to Google Chrome Security Team (SkyLined).
* [55745] Medium Cross-origin video theft with canvas. Credit to Nirankush Panchbhai and Microsoft Vulnerability Research (MSVR).
* [56237] Low Browser crash with HTML5 databases. Credit to Google Chrome Security Team (Inferno).
* [58319] Low Prevent excessive file dialogs, possibly leading to browser crash. Credit to Cezary Tomczak (gosu.pl).
* [$500] [59554] High Use after free in history handling. Credit to Stefan Troger.
* [Linux / Mac] [59817] Medium Make sure the “dangerous file types” list is uptodate with the Windows platforms. Credit to Billy Rios of the Google Security Team.
* [61701] Low Browser crash with HTTP proxy authentication. Credit to Mohammed Bouhlel.
* [61653] Medium Out-of-bounds read regression in WebM video support. Credit to Google Chrome Security Team (Chris Evans), based on earlier testcases from Mozilla and Microsoft (MSVR).
* [$1000] [62127] High Crash due to bad indexing with malformed video. Credit to miaubiz.
* [62168] Medium Possible browser memory corruption via malicious privileged extension. Credit to kuzzcc.
* [$1000] [62401] High Use after free with SVG animations. Credit to Sławomir Błażek.
* [$500] [63051] Medium Use after free in mouse dragging event handling. Credit to kuzzcc.
* [$1000] [63444] High Double free in XPath handling. Credit to Yang Dingning from NCNIPC, Graduate University of Chinese Academy of Sciences.
We would like to offer special thanks -- and a number of rewards -- to Aki Helin of OUSPG for his extensive help with the new PDF feature. We’d also like to extend thanks to Sergey Glazunov and Marc Schoenefeld for finding bugs during the development cycle such that they never reached a stable build.
Full details about the changes are available in the SVN revision log. If you find new issues, please let us know by filing a bug. Want to change to another Chrome release channel? Find out how.
-DOWNLOAD-
Google Chrome 8.0.552.215 (Windows) / Google Chrome 8.0.552.215 (Mac) / Google Chrome 8.0.552.215 (Linux)
Tags:
chrome,
google,
web browser
Friday, November 5, 2010
Google Chrome 7.0.517.44
(2010.11.04)
Google Chrome has been updated to 7.0.517.44 for Windows, Mac, Linux and Chrome Frame on the Stable channel. Along with the security fixes below, this build has an updated version of Flash.
Security fixes and rewards:
Please see the Chromium security page for more detail. Note that the referenced bugs may be kept private until a majority of our users are up to date with the fix.
* [51602] High Use-after-free in text editing. Credit to David Bloom of the Google Security Team, Google Chrome Security Team (Inferno) and Google Chrome Security Team (Cris Neckar).
* [$1000] [55257] High Memory corruption with enormous text area. Credit to wushi of team509.
* [$1000] [58657] High Bad cast with the SVG use element. Credit to the kuzzcc.
* [$1000] [58731] High Invalid memory read in XPath handling. Credit to Bui Quang Minh from Bkis (www.bkis.com).
* [$500] [58741] High Use-after-free in text control selections. Credit to “vkouchna”.
* [$1000] [Linux only] [59320] High Integer overflows in font handling. Credit to Aki Helin of OUSPG.
* [$1000] [60055] High Memory corruption in libvpx. Credit to Christoph Diehl.
* [$500] [60238] High Bad use of destroyed frame object. Credit to various developers, including “gundlach”.
* [$500] [60327] [60769] [61255] High Type confusions with event objects. Credit to “fam.lam” and Google Chrome Security Team (Inferno).
* [$1000] [60688] High Out-of-bounds array access in SVG handling. Credit to wushi of team509.
-DOWNLOAD-
Google Chrome 7.0.517.44 (Windows) / Google Chrome 7.0.517.44 (Mac) / Google Chrome 7.0.517.44 (Linux)
Google Chrome has been updated to 7.0.517.44 for Windows, Mac, Linux and Chrome Frame on the Stable channel. Along with the security fixes below, this build has an updated version of Flash.
Security fixes and rewards:
Please see the Chromium security page for more detail. Note that the referenced bugs may be kept private until a majority of our users are up to date with the fix.
* [51602] High Use-after-free in text editing. Credit to David Bloom of the Google Security Team, Google Chrome Security Team (Inferno) and Google Chrome Security Team (Cris Neckar).
* [$1000] [55257] High Memory corruption with enormous text area. Credit to wushi of team509.
* [$1000] [58657] High Bad cast with the SVG use element. Credit to the kuzzcc.
* [$1000] [58731] High Invalid memory read in XPath handling. Credit to Bui Quang Minh from Bkis (www.bkis.com).
* [$500] [58741] High Use-after-free in text control selections. Credit to “vkouchna”.
* [$1000] [Linux only] [59320] High Integer overflows in font handling. Credit to Aki Helin of OUSPG.
* [$1000] [60055] High Memory corruption in libvpx. Credit to Christoph Diehl.
* [$500] [60238] High Bad use of destroyed frame object. Credit to various developers, including “gundlach”.
* [$500] [60327] [60769] [61255] High Type confusions with event objects. Credit to “fam.lam” and Google Chrome Security Team (Inferno).
* [$1000] [60688] High Out-of-bounds array access in SVG handling. Credit to wushi of team509.
-DOWNLOAD-
Google Chrome 7.0.517.44 (Windows) / Google Chrome 7.0.517.44 (Mac) / Google Chrome 7.0.517.44 (Linux)
Tags:
chrome,
google,
web browser
Wednesday, October 20, 2010
Google Chrome 7.0.517.43
(2010.10.19)
Update: Google Chrome Frame, 7.0.517.43, has been release to stable and beta channels.
Google Chrome 7.0.517.41 has been released to the stable and beta channels for Windows, Mac, and Linux. Updates from the previous stable release include:
* Hundreds of bug fixes
* An updated HTML5 parser
* File API
* Directory upload via input tag
More information on these and other changes in Chrome 7 can be found on the Google Chrome blog.
Security fixes and rewards:
Please see the Chromium security page for more detail. Note that the referenced bugs may be kept private until a majority of our users are up to date with the fix.
* [48225] [51727] Medium Possible autofill / autocomplete profile spamming. Credit to Google Chrome Security Team (Inferno).
* [48857] High Crash with forms. Credit to the Chromium development community.
* [50428] Critical Browser crash with form autofill. Credit to the Chromium development community.
* [$500] [51680] High Possible URL spoofing on page unload. Credit to kuzzcc; plus independent discovery by Jordi Chancel.
* [53002] Low Pop-up block bypass. Credit to kuzzcc.
* [53985] Medium Crash on shutdown with Web Sockets. Credit to the Chromium development community.
* [Linux only] [54132] Low Bad construction of PATH variable. Credit to Dan Rosenberg, Virtual Security Research.
* [$500] [54500] High Possible memory corruption with animated GIF. Credit to Simon Schaak.
* [Linux only] [54794] High Failure to sandbox worker processes on Linux. Credit to Google Chrome Security Team (Chris Evans).
* [56451] High Stale elements in an element map. Credit to Michal Zalewski of the Google Security Team.
In addition, we would like to credit Aki Helin of OUSPG and kuzzcc for finding bugs during the development cycle such that they never reached a stable build.
-DOWNLOAD-
Google Chrome 7.0.517.41 (Windows) / Google Chrome 7.0.517.41 (Mac) / Google Chrome 7.0.517.41 (Linux)
Update: Google Chrome Frame, 7.0.517.43, has been release to stable and beta channels.
Google Chrome 7.0.517.41 has been released to the stable and beta channels for Windows, Mac, and Linux. Updates from the previous stable release include:
* Hundreds of bug fixes
* An updated HTML5 parser
* File API
* Directory upload via input tag
More information on these and other changes in Chrome 7 can be found on the Google Chrome blog.
Security fixes and rewards:
Please see the Chromium security page for more detail. Note that the referenced bugs may be kept private until a majority of our users are up to date with the fix.
* [48225] [51727] Medium Possible autofill / autocomplete profile spamming. Credit to Google Chrome Security Team (Inferno).
* [48857] High Crash with forms. Credit to the Chromium development community.
* [50428] Critical Browser crash with form autofill. Credit to the Chromium development community.
* [$500] [51680] High Possible URL spoofing on page unload. Credit to kuzzcc; plus independent discovery by Jordi Chancel.
* [53002] Low Pop-up block bypass. Credit to kuzzcc.
* [53985] Medium Crash on shutdown with Web Sockets. Credit to the Chromium development community.
* [Linux only] [54132] Low Bad construction of PATH variable. Credit to Dan Rosenberg, Virtual Security Research.
* [$500] [54500] High Possible memory corruption with animated GIF. Credit to Simon Schaak.
* [Linux only] [54794] High Failure to sandbox worker processes on Linux. Credit to Google Chrome Security Team (Chris Evans).
* [56451] High Stale elements in an element map. Credit to Michal Zalewski of the Google Security Team.
In addition, we would like to credit Aki Helin of OUSPG and kuzzcc for finding bugs during the development cycle such that they never reached a stable build.
-DOWNLOAD-
Google Chrome 7.0.517.41 (Windows) / Google Chrome 7.0.517.41 (Mac) / Google Chrome 7.0.517.41 (Linux)
Tags:
chrome,
google,
web browser
Thursday, September 23, 2010
Google Chrome 6.0.472.63
(2010.09.22)
Google Chrome has been updated to 6.0.472.63 for all platforms on the Stable and Beta channels. This version contains a fix in V8 for direct loading of global function prototypes [V8 r5483].
More details about additional changes are available in the SVN revision log. If you find new issues, please let us know by filing a bug. Want to change to another Chrome release channel? Find out how.
-DOWNLOAD-
Google Chrome 6.0.472.63 (Windows) / Google Chrome 6.0.472.63 (Mac) / Google Chrome 6.0.472.63 (Linux)
Google Chrome has been updated to 6.0.472.63 for all platforms on the Stable and Beta channels. This version contains a fix in V8 for direct loading of global function prototypes [V8 r5483].
More details about additional changes are available in the SVN revision log. If you find new issues, please let us know by filing a bug. Want to change to another Chrome release channel? Find out how.
-DOWNLOAD-
Google Chrome 6.0.472.63 (Windows) / Google Chrome 6.0.472.63 (Mac) / Google Chrome 6.0.472.63 (Linux)
Tags:
chrome,
google,
web browser
Saturday, September 18, 2010
Google Chrome 6.0.472.62
(2010.09.17)
Google Chrome has been updated to 6.0.472.62 for Windows, Linux and Mac on the Stable channel. In addition, all of the above plus Chrome Frame have been updated on the Beta channel.
Along with the security fixes listed below, this version includes an updated version of the Flash Plugin with a fix for a security vulnerability.
Security fixes and rewards
Please see the Chromium security page for more detail. Note that the referenced bugs may be kept private until a majority of our users are up to date with the fix.
* [$500] [55114] High Bad cast with malformed SVG. Credit to wushi of team 509.
* [55119] Critical Buffer mismanagement in the SPDY protocol. Credit to Ron Ten-Hove of Google.
* [$1000] [55350] High Cross-origin property pollution. Credit to Stefano Di Paola of MindedSecurity.
More details about additional changes are available in the SVN revision log. If you find new issues, please let us know by filing a bug. Want to change to another Chrome release channel - find out how.
-DOWNLOAD-
Google Chrome 6.0.472.62 (Windows) / Google Chrome 6.0.472.62 (Mac) / Google Chrome 6.0.472.62 (Linux)
Google Chrome has been updated to 6.0.472.62 for Windows, Linux and Mac on the Stable channel. In addition, all of the above plus Chrome Frame have been updated on the Beta channel.
Along with the security fixes listed below, this version includes an updated version of the Flash Plugin with a fix for a security vulnerability.
Security fixes and rewards
Please see the Chromium security page for more detail. Note that the referenced bugs may be kept private until a majority of our users are up to date with the fix.
* [$500] [55114] High Bad cast with malformed SVG. Credit to wushi of team 509.
* [55119] Critical Buffer mismanagement in the SPDY protocol. Credit to Ron Ten-Hove of Google.
* [$1000] [55350] High Cross-origin property pollution. Credit to Stefano Di Paola of MindedSecurity.
More details about additional changes are available in the SVN revision log. If you find new issues, please let us know by filing a bug. Want to change to another Chrome release channel - find out how.
-DOWNLOAD-
Google Chrome 6.0.472.62 (Windows) / Google Chrome 6.0.472.62 (Mac) / Google Chrome 6.0.472.62 (Linux)
Tags:
chrome,
google,
web browser
Wednesday, September 15, 2010
Google Chrome 6.0.472.59
(2010.10.14)
Google Chrome 6.0.472.59 has been released to the Stable and Beta channels for Windows, Mac, and Linux. In addition, it has been released to the beta channel for Chrome Frame.
Security fixes and rewards:
Please see the Chromium security page for more detail. Note that the referenced bugs may be kept private until a majority of our users are up to date with the fix.
* [$500] [50250] High Use-after-free when using document APIs during parse. Credit to David Weston of Microsoft + Microsoft Vulnerability Research (MSVR) and wushi of team 509 (independent discoveries).
* [$1000] [50712] High Use-after-free in SVG styles. Credit to kuzzcc.
* [$500] [51252] High Use-after-free with nested SVG elements. Credit to kuzzcc.
* [Linux only] [51709] Low Possible browser assert in cursor handling. Credit to “magnusmorton”.
* [$500] [51919] High Race condition in console handling. Credit to kuzzcc.
* [53176] Low Unlikely browser crash in pop-up blocking. Credit to kuzzcc.
* [$500 x 2] [Mac only] [53361] Critical Fix bug 45400 properly on the Mac. Credit to Sergey Glazunov and “remy.saissy”.
* [$500] [53394] High Memory corruption in Geolocation. Credit to kuzzcc.
* [Linux only] [53930] High Memory corruption in Khmer handling. Credit to Google Chrome Security Team (Chris Evans).
* [54006] Low Failure to prompt for extension history access. Credit to “adriennefelt”.
More details about additional changes are available in the svn revision log. If you find new issues, please let us know by filing a bug. Want to change to another Chrome release channel - find out how.
-DOWNLOAD-
Google Chrome 6.0.472.59 (Windows) / Google Chrome 6.0.472.59 (Mac) / Google Chrome 6.0.472.59 (Linux)
Google Chrome 6.0.472.59 has been released to the Stable and Beta channels for Windows, Mac, and Linux. In addition, it has been released to the beta channel for Chrome Frame.
Security fixes and rewards:
Please see the Chromium security page for more detail. Note that the referenced bugs may be kept private until a majority of our users are up to date with the fix.
* [$500] [50250] High Use-after-free when using document APIs during parse. Credit to David Weston of Microsoft + Microsoft Vulnerability Research (MSVR) and wushi of team 509 (independent discoveries).
* [$1000] [50712] High Use-after-free in SVG styles. Credit to kuzzcc.
* [$500] [51252] High Use-after-free with nested SVG elements. Credit to kuzzcc.
* [Linux only] [51709] Low Possible browser assert in cursor handling. Credit to “magnusmorton”.
* [$500] [51919] High Race condition in console handling. Credit to kuzzcc.
* [53176] Low Unlikely browser crash in pop-up blocking. Credit to kuzzcc.
* [$500 x 2] [Mac only] [53361] Critical Fix bug 45400 properly on the Mac. Credit to Sergey Glazunov and “remy.saissy”.
* [$500] [53394] High Memory corruption in Geolocation. Credit to kuzzcc.
* [Linux only] [53930] High Memory corruption in Khmer handling. Credit to Google Chrome Security Team (Chris Evans).
* [54006] Low Failure to prompt for extension history access. Credit to “adriennefelt”.
More details about additional changes are available in the svn revision log. If you find new issues, please let us know by filing a bug. Want to change to another Chrome release channel - find out how.
-DOWNLOAD-
Google Chrome 6.0.472.59 (Windows) / Google Chrome 6.0.472.59 (Mac) / Google Chrome 6.0.472.59 (Linux)
Tags:
chrome,
google,
web browser
Thursday, September 9, 2010
Google Chrome 6.0.472.55
(2010.09.07)
The Stable and Beta channels of Chrome have been updated to 6.0.472.55 for Windows, Mac, and Linux. This version contains the following fixes:
All
* [r58038] [r58039] Failures when using autocomplete (issue 51727, 52940)
* [r58106] Default search engine settings wiped out (issue 10913)
* Shift reload not working (issue 1906)
Windows
* [r58190] Importing data from other browsers when chrome is set as default (bug 53655)
* [r58288] Chrome can’t be made default browser when it already exists (bug 53656)
More details about additional changes are available in the svn revision log. If you find new issues, please let us know by filing a bug. Want to change to another Chrome release channel - find out how.
-DOWNLOAD-
Google Chrome 6.0.472.55 (Windows) / Google Chrome 6.0.472.55 (Mac) / Google Chrome 6.0.472.55 (Linux)
The Stable and Beta channels of Chrome have been updated to 6.0.472.55 for Windows, Mac, and Linux. This version contains the following fixes:
All
* [r58038] [r58039] Failures when using autocomplete (issue 51727, 52940)
* [r58106] Default search engine settings wiped out (issue 10913)
* Shift reload not working (issue 1906)
Windows
* [r58190] Importing data from other browsers when chrome is set as default (bug 53655)
* [r58288] Chrome can’t be made default browser when it already exists (bug 53656)
More details about additional changes are available in the svn revision log. If you find new issues, please let us know by filing a bug. Want to change to another Chrome release channel - find out how.
-DOWNLOAD-
Google Chrome 6.0.472.55 (Windows) / Google Chrome 6.0.472.55 (Mac) / Google Chrome 6.0.472.55 (Linux)
Tags:
chrome,
google,
web browser
Friday, September 3, 2010
Google Chrome 6.0.472.53
(2010.09.02)
Google Chrome 6.0.472.53 has been released to the stable and beta channels for Windows, Mac, and Linux. Updates from the previous stable release include:
* Updated UI
* Form Autofill
* Syncing of extensions and Autofill data
* Increased speed and stability
More information on these and other changes in Chrome 6 can be found on the Google Chrome blog. Download Chrome today!
Security fixes and rewards:
Please see the Chromium security page for more detail. Note that the referenced bugs may be kept private until a majority of our users are up to date with the fix.
* [34414] Low Pop-up blocker bypass with blank frame target. Credit to Google Chrome Security Team (Inferno) and “ironfist99”.
* [37201] Medium URL bar visual spoofing with homographic sequences. Credit to Chris Weber of Casaba Security.
* [41654] Medium Apply more restrictions on setting clipboard content. Credit to Brook Novak.
* [45659] High Stale pointer with SVG filters. Credit to Tavis Ormandy of the Google Security Team.
* [45876] Medium Possible installed extension enumeration. Credit to Lostmon.
* [46750] [51846] Low Browser NULL crash with WebSockets. Credit to Google Chrome Security Team (SkyLined), Google Chrome Security Team (Justin Schuh) and Keith Campbell.
* [$1000] [50386] High Use-after-free in Notifications presenter. Credit to Sergey Glazunov.
* [50839] High Notification permissions memory corruption. Credit to Michal Zalewski of the Google Security Team and Google Chrome Security Team (SkyLined).
* [$1337] [51630] [51739] High Integer errors in WebSockets. Credit to Keith Campbell and Google Chrome Security Team (Cris Neckar).
* [$500] [51653] High Memory corruption with counter nodes. Credit to kuzzcc.
* [51727] Low Avoid storing excessive autocomplete entries. Credit to Google Chrome Security Team (Inferno).
* [52443] High Stale pointer in focus handling. Credit to VUPEN Vulnerability Research Team (VUPEN-SR-2010-249).
* [$1000] [52682] High Sandbox parameter deserialization error. Credit to Ashutosh Mehra and Vineet Batra of the Adobe Reader Sandbox Team.
* [$500] [53001] Medium Cross-origin image theft. Credit to Isaac Dawson.
This release also fixes [51070] (Windows kernel bug workaround; credit to Marc Schoenefeld), which was incorrectly declared fixed in version 5.0.375.127.
In addition, we would like to credit Google Chrome Security Team (Inferno), James Robinson (Chromium development community), Google Chrome Security Team (Cris Neckar), Aki Helin of OUSPG, Fred Akalin (Chromium development community), Anna Popivanova, “myusualnickname”, Michal Zalewski of the Google Security Team, kuzzcc and Aaron Boodman (Chromium development community) for finding bugs during the development cycle such that they never reached a stable build.
If you find new issues, please let us know by filing a bug. If you would like to use the stable channel, you can find out more about changing your Chrome channel.
-DOWNLOAD-
Google Chrome 6.0.472.53 (Windows) / Google Chrome 6.0.472.53 (Mac) / Google Chrome 6.0.472.53 (Linux)
Google Chrome 6.0.472.53 has been released to the stable and beta channels for Windows, Mac, and Linux. Updates from the previous stable release include:
* Updated UI
* Form Autofill
* Syncing of extensions and Autofill data
* Increased speed and stability
More information on these and other changes in Chrome 6 can be found on the Google Chrome blog. Download Chrome today!
Security fixes and rewards:
Please see the Chromium security page for more detail. Note that the referenced bugs may be kept private until a majority of our users are up to date with the fix.
* [34414] Low Pop-up blocker bypass with blank frame target. Credit to Google Chrome Security Team (Inferno) and “ironfist99”.
* [37201] Medium URL bar visual spoofing with homographic sequences. Credit to Chris Weber of Casaba Security.
* [41654] Medium Apply more restrictions on setting clipboard content. Credit to Brook Novak.
* [45659] High Stale pointer with SVG filters. Credit to Tavis Ormandy of the Google Security Team.
* [45876] Medium Possible installed extension enumeration. Credit to Lostmon.
* [46750] [51846] Low Browser NULL crash with WebSockets. Credit to Google Chrome Security Team (SkyLined), Google Chrome Security Team (Justin Schuh) and Keith Campbell.
* [$1000] [50386] High Use-after-free in Notifications presenter. Credit to Sergey Glazunov.
* [50839] High Notification permissions memory corruption. Credit to Michal Zalewski of the Google Security Team and Google Chrome Security Team (SkyLined).
* [$1337] [51630] [51739] High Integer errors in WebSockets. Credit to Keith Campbell and Google Chrome Security Team (Cris Neckar).
* [$500] [51653] High Memory corruption with counter nodes. Credit to kuzzcc.
* [51727] Low Avoid storing excessive autocomplete entries. Credit to Google Chrome Security Team (Inferno).
* [52443] High Stale pointer in focus handling. Credit to VUPEN Vulnerability Research Team (VUPEN-SR-2010-249).
* [$1000] [52682] High Sandbox parameter deserialization error. Credit to Ashutosh Mehra and Vineet Batra of the Adobe Reader Sandbox Team.
* [$500] [53001] Medium Cross-origin image theft. Credit to Isaac Dawson.
This release also fixes [51070] (Windows kernel bug workaround; credit to Marc Schoenefeld), which was incorrectly declared fixed in version 5.0.375.127.
In addition, we would like to credit Google Chrome Security Team (Inferno), James Robinson (Chromium development community), Google Chrome Security Team (Cris Neckar), Aki Helin of OUSPG, Fred Akalin (Chromium development community), Anna Popivanova, “myusualnickname”, Michal Zalewski of the Google Security Team, kuzzcc and Aaron Boodman (Chromium development community) for finding bugs during the development cycle such that they never reached a stable build.
If you find new issues, please let us know by filing a bug. If you would like to use the stable channel, you can find out more about changing your Chrome channel.
-DOWNLOAD-
Google Chrome 6.0.472.53 (Windows) / Google Chrome 6.0.472.53 (Mac) / Google Chrome 6.0.472.53 (Linux)
Tags:
chrome,
google,
web browser
Friday, August 20, 2010
Google Chrome 5.0.375.127
(2010.08.19)
Google Chrome 5.0.375.127 has been released to the Stable Channel on Windows, Mac, and Linux.
Security fixes and rewards:
Please see the Chromium security page for more detail. Note that the referenced bugs may be kept private until a majority of our users are up to date with the fix.
Aside from the listed security bugs fixed in Chromium, we have also deployed a workaround for a critical vulnerability where the root cause lies in an external component. Credit and $1337 to Marc Schoenefeld for enabling us to work around another Windows kernel bug [51070].
* [$1337] [45400] Critical Memory corruption with file dialog. Credit to Sergey Glazunov.
* [$500] [49596] High Memory corruption with SVGs. Credit to wushi of team509.
* [$500] [49628] High Bad cast with text editing. Credit to wushi of team509.
* [$1000] [49964] High Possible address bar spoofing with history bug. Credit to Mike Taylor.
* [$2000] [50515] [51835] High Memory corruption in MIME type handling. Credit to Sergey Glazunov.
* [$1337] [50553] Critical Crash on shutdown due to notifications bug. Credit to Sergey Glazunov.
* [51146] Medium Stop omnibox autosuggest if the user might be about to type a password. Credit to Robert Hansen.
* [$1000] [51654] High Memory corruption with Ruby support. Credit to kuzzcc.
* [$1000] [51670] High Memory corruption with Geolocation support. Credit to kuzzcc.
If you find issues, please let us know: http://code.google.com/p/chromium/issues/entry
-DOWNLOAD-
Google Chrome 5.0.375.127 (Windows) / Google Chrome 5.0.375.127 (Mac) / Google Chrome 5.0.375.127 (Linux)
Google Chrome 5.0.375.127 has been released to the Stable Channel on Windows, Mac, and Linux.
Security fixes and rewards:
Please see the Chromium security page for more detail. Note that the referenced bugs may be kept private until a majority of our users are up to date with the fix.
Aside from the listed security bugs fixed in Chromium, we have also deployed a workaround for a critical vulnerability where the root cause lies in an external component. Credit and $1337 to Marc Schoenefeld for enabling us to work around another Windows kernel bug [51070].
* [$1337] [45400] Critical Memory corruption with file dialog. Credit to Sergey Glazunov.
* [$500] [49596] High Memory corruption with SVGs. Credit to wushi of team509.
* [$500] [49628] High Bad cast with text editing. Credit to wushi of team509.
* [$1000] [49964] High Possible address bar spoofing with history bug. Credit to Mike Taylor.
* [$2000] [50515] [51835] High Memory corruption in MIME type handling. Credit to Sergey Glazunov.
* [$1337] [50553] Critical Crash on shutdown due to notifications bug. Credit to Sergey Glazunov.
* [51146] Medium Stop omnibox autosuggest if the user might be about to type a password. Credit to Robert Hansen.
* [$1000] [51654] High Memory corruption with Ruby support. Credit to kuzzcc.
* [$1000] [51670] High Memory corruption with Geolocation support. Credit to kuzzcc.
If you find issues, please let us know: http://code.google.com/p/chromium/issues/entry
-DOWNLOAD-
Google Chrome 5.0.375.127 (Windows) / Google Chrome 5.0.375.127 (Mac) / Google Chrome 5.0.375.127 (Linux)
Tags:
chrome,
google,
web browser
Wednesday, August 11, 2010
Google Chrome 5.0.375.126
(2010.08.10)
Google Chrome 5.0.375.126 has been released to the Stable channel on Linux, Mac, and Windows. This version contains an updated version of the Flash plugin.
If you find issues, please let us know: http://code.google.com/p/chromium/issues/entry
-DOWNLOAD-
Google Chrome 5.0.375.126 (Windows) / Google Chrome 5.0.375.126 (Mac) / Google Chrome 5.0.375.126 (Linux)
Google Chrome 5.0.375.126 has been released to the Stable channel on Linux, Mac, and Windows. This version contains an updated version of the Flash plugin.
If you find issues, please let us know: http://code.google.com/p/chromium/issues/entry
-DOWNLOAD-
Google Chrome 5.0.375.126 (Windows) / Google Chrome 5.0.375.126 (Mac) / Google Chrome 5.0.375.126 (Linux)
Tags:
chrome,
google,
web browser
Wednesday, July 28, 2010
Google Chrome 5.0.375.125
(2010.07.26)
Google Chrome 5.0.375.125 has been released to the Stable channel on Linux, Mac, Windows, and Chrome Frame.
Security fixes and rewards:
Please see the Chromium security page for more detail. Note that the referenced bugs may be kept private until a majority of our users are up to date with the fix.
Aside from the listed security bugs fixed in Chromium, we have also deployed workarounds for two critical vulnerabilities where the root cause lies in external components. Credit and $1337 to Marc Schoenefeld for enabling us to work around a Windows kernel bug [48283]. Credit and $1337 to Simon Berry-Byrne for enabling us to work around a glibc bug [48733].
* [$500] [42736] Medium Memory contents disclosure in layout code. Credit to Michail Nikolaev.
* [$500] [43813] High Issue with large canvases. Credit to sp3x of SecurityReason.com.
* [$500] [47866] High Memory corruption in rendering code. Credit to Jose A. Vazquez.
* [$500] [48284] High Memory corruption in SVG handling. Credit to Aki Helin of OUSPG.
* [48597] Low Avoid hostname truncation and incorrect eliding. Credit to Google Chrome Security Team (Inferno).
If you find issues, please let us know: http://code.google.com/p/chromium/issues/entry
-DOWNLOAD-
Google Chrome 5.0.375.125 (Windows) / Google Chrome 5.0.375.125 (Mac) / Google Chrome 5.0.375.125 (Linux)
Google Chrome 5.0.375.125 has been released to the Stable channel on Linux, Mac, Windows, and Chrome Frame.
Security fixes and rewards:
Please see the Chromium security page for more detail. Note that the referenced bugs may be kept private until a majority of our users are up to date with the fix.
Aside from the listed security bugs fixed in Chromium, we have also deployed workarounds for two critical vulnerabilities where the root cause lies in external components. Credit and $1337 to Marc Schoenefeld for enabling us to work around a Windows kernel bug [48283]. Credit and $1337 to Simon Berry-Byrne for enabling us to work around a glibc bug [48733].
* [$500] [42736] Medium Memory contents disclosure in layout code. Credit to Michail Nikolaev.
* [$500] [43813] High Issue with large canvases. Credit to sp3x of SecurityReason.com.
* [$500] [47866] High Memory corruption in rendering code. Credit to Jose A. Vazquez.
* [$500] [48284] High Memory corruption in SVG handling. Credit to Aki Helin of OUSPG.
* [48597] Low Avoid hostname truncation and incorrect eliding. Credit to Google Chrome Security Team (Inferno).
If you find issues, please let us know: http://code.google.com/p/chromium/issues/entry
-DOWNLOAD-
Google Chrome 5.0.375.125 (Windows) / Google Chrome 5.0.375.125 (Mac) / Google Chrome 5.0.375.125 (Linux)
Tags:
chrome,
google,
web browser
Friday, July 2, 2010
Google Chrome 5.0.375.99
(2010.07.01)
Google Chrome 5.0.375.99 has been released to the Stable channel on Linux, Mac, and Windows.
This release fixes the following security issues:
* [42396] Low OOB read with WebGL. Credit to Sergey Glazunov; Google Chrome Security Team (SkyLined).
* [42575] [42980] Medium Isolate sandboxed iframes more strongly. Credit to sirdarckcat of Google Security Team.
* [$500] [43488] High Memory corruption with invalid SVGs. Credit to Aki Hekin of OUSPG; wushi of team509.
* [$500] [44424] High Memory corruption in bidi algorithm. Credit to wushi of team509.
* [45164] Low Crash with invalid image. Credit to javg0x83.
* [$1000] [45983] High Memory corruption with invalid PNG (libpng bug). Credit to Aki Helin of OUSPG.
* [$500] [46360] High Memory corruption in CSS style rendering. Credit to wushi of team509.
* [46575] Low Annoyance with print dialogs. Credit to Mats Ahlgren.
* [47056] Low Crash with modal dialogs. Credit to Aki Helin of OUSPG.
If you find issues, please let us know: http://code.google.com/p/chromium/issues/entry
-DOWNLOAD-
Google Chrome 5.0.375.99 (Windows) / Google Chrome 5.0.375.99 (Mac) / Google Chrome 5.0.375.99 (Linux)
Google Chrome 5.0.375.99 has been released to the Stable channel on Linux, Mac, and Windows.
This release fixes the following security issues:
* [42396] Low OOB read with WebGL. Credit to Sergey Glazunov; Google Chrome Security Team (SkyLined).
* [42575] [42980] Medium Isolate sandboxed iframes more strongly. Credit to sirdarckcat of Google Security Team.
* [$500] [43488] High Memory corruption with invalid SVGs. Credit to Aki Hekin of OUSPG; wushi of team509.
* [$500] [44424] High Memory corruption in bidi algorithm. Credit to wushi of team509.
* [45164] Low Crash with invalid image. Credit to javg0x83.
* [$1000] [45983] High Memory corruption with invalid PNG (libpng bug). Credit to Aki Helin of OUSPG.
* [$500] [46360] High Memory corruption in CSS style rendering. Credit to wushi of team509.
* [46575] Low Annoyance with print dialogs. Credit to Mats Ahlgren.
* [47056] Low Crash with modal dialogs. Credit to Aki Helin of OUSPG.
If you find issues, please let us know: http://code.google.com/p/chromium/issues/entry
-DOWNLOAD-
Google Chrome 5.0.375.99 (Windows) / Google Chrome 5.0.375.99 (Mac) / Google Chrome 5.0.375.99 (Linux)
Tags:
chrome,
google,
web browser
Friday, June 25, 2010
Google Chrome 5.0.375.86
(2010.06.24)
Google Chrome 5.0.375.86 has been released to the Stable channel on Linux, Mac, and Windows.
The integrated flash player has been enabled by default and the following security issues were resolved:
* [38105] Medium XSS via application/json response (regression). Credit to Ben Davis for original discovery and Emanuele Gentili for regression discovery.
* [43322] Medium Memory error in video handling. Credit to Mark Dowd under contract to Google Chrome Security Team.
* [43967] High Subresource displayed in omnibox loading. Credit to Michal Zalewski of Google Security Team.
* [45267] High Memory error in video handling. Credit to Google Chrome Security Team (Cris Neckar).
* [$500] [46126] High Stale pointer in x509-user-cert response. Credit to Rodrigo Marcos of SECFORCE.
If you find issues, please let us know: http://code.google.com/p/chromium/issues/entry
-DOWNLOAD-
Google Chrome 5.0.375.86 (Windows) / Google Chrome 5.0.375.86 (Mac) / Google Chrome 5.0.375.86 (Linux)
Google Chrome 5.0.375.86 has been released to the Stable channel on Linux, Mac, and Windows.
The integrated flash player has been enabled by default and the following security issues were resolved:
* [38105] Medium XSS via application/json response (regression). Credit to Ben Davis for original discovery and Emanuele Gentili for regression discovery.
* [43322] Medium Memory error in video handling. Credit to Mark Dowd under contract to Google Chrome Security Team.
* [43967] High Subresource displayed in omnibox loading. Credit to Michal Zalewski of Google Security Team.
* [45267] High Memory error in video handling. Credit to Google Chrome Security Team (Cris Neckar).
* [$500] [46126] High Stale pointer in x509-user-cert response. Credit to Rodrigo Marcos of SECFORCE.
If you find issues, please let us know: http://code.google.com/p/chromium/issues/entry
-DOWNLOAD-
Google Chrome 5.0.375.86 (Windows) / Google Chrome 5.0.375.86 (Mac) / Google Chrome 5.0.375.86 (Linux)
Tags:
chrome,
google,
web browser
Thursday, June 10, 2010
Google Chrome 5.0.375.70
(2010.06.08)
Google Chrome 5.0.375.70 has been released to the Stable channel on Linux, Mac, and Windows.
This release fixes the following security issues:
* [15766] Medium Cross-origin keystroke redirection. Credit to Michal Zalewski of Google Security Team.
* [$2000] [39985] High Cross-origin bypass in DOM methods. Credit to Sergey Glazunov.
* [$500] [42723] High Memory error in table layout. Credit to wushi of team509.
* [Linux only] [43304] High Linux sandbox escape. Credit to Mark Dowd under contract to Google Chrome Security Team.
* [43307] High Bitmap stale pointer. Credit to Mark Dowd under contract to Google Chrome Security Team.
* [43315] High Memory corruption in DOM node normalization. Credit to Mark Dowd under contract to Google Chrome Security Team.
* [43487] High Memory corruption in text transforms. Credit to wushi of team509.
* [43902] Medium XSS in innerHTML property of textarea. Credit to sirdarckcat of Google Security Team.
* [44740] High Memory corruption in font handling. Credit: Apple.
* [44868] High Geolocation events fire after document deletion. Credit to Google Chrome Security Team (Justin Schuh).
* [44955] High Memory corruption in rendering of list markers. Credit: Apple.
If you find issues, please let us know: http://code.google.com/p/chromium/issues/entry
-DOWNLOAD-
Google Chrome 5.0.375.70
Google Chrome 5.0.375.70 has been released to the Stable channel on Linux, Mac, and Windows.
This release fixes the following security issues:
* [15766] Medium Cross-origin keystroke redirection. Credit to Michal Zalewski of Google Security Team.
* [$2000] [39985] High Cross-origin bypass in DOM methods. Credit to Sergey Glazunov.
* [$500] [42723] High Memory error in table layout. Credit to wushi of team509.
* [Linux only] [43304] High Linux sandbox escape. Credit to Mark Dowd under contract to Google Chrome Security Team.
* [43307] High Bitmap stale pointer. Credit to Mark Dowd under contract to Google Chrome Security Team.
* [43315] High Memory corruption in DOM node normalization. Credit to Mark Dowd under contract to Google Chrome Security Team.
* [43487] High Memory corruption in text transforms. Credit to wushi of team509.
* [43902] Medium XSS in innerHTML property of textarea. Credit to sirdarckcat of Google Security Team.
* [44740] High Memory corruption in font handling. Credit: Apple.
* [44868] High Geolocation events fire after document deletion. Credit to Google Chrome Security Team (Justin Schuh).
* [44955] High Memory corruption in rendering of list markers. Credit: Apple.
If you find issues, please let us know: http://code.google.com/p/chromium/issues/entry
-DOWNLOAD-
Google Chrome 5.0.375.70
Tags:
chrome,
google,
web browser
Wednesday, May 26, 2010
Google Chrome 5.0.375.55
(2010.05.25)
Google Chrome 5.0.375.55 has been released to the Stable channel for Linux, Mac and Windows.
For more details about the new features in the release, over our previous stable release 4.1, please see the Official Google Chrome blog.
Security Fixes:
Please see the Chromium security page for more detail. Note that the referenced bugs may be kept private until a majority of our users are up to date with the fix.
* [7713] Medium Canonicalize URLs closer to the Safe Browsing specification. Credit to Brett Wilson of the Chromium development community.
* [16535] High Possible URL bar spoofing via unload event handlers. Credit to Michal Zalewski, Google Security Team.
* [30079] Medium Memory error in Safe Browsing interaction. Credit to Google Chrome Security Team (SkyLined).
* [39740] Medium Bypass of whitelist-mode plugin blocker. Credit to Darin Fisher of the Chromium development community.
* [41469] Medium Memory error with drag + drop. Credit to kuzzcc.
* [42228] High Incorrect execution of Javascript in the extension context. Credit to Andrey Kosyakov of the Chromium development community.
In addition, we fixed a range of minor issues such as non-exploitable crashes, hangs and other annoyances. Credit to Sumit Gwalani; Google Security Team, sirdarckcat; Google Security Team, Google Chrome Security Team (Inferno), Carlos Ghan, WHK; elhacker.net, x41, Aki Helin; OUSPG, Jordi Chancel, kuzzcc, Robert Swiecki; Google Security Team, Tavis Ormandy; Google Security Team and Florent; Skyrecon Systems.
Also, we would like to extend our thanks to the following people who helped find bugs so we could fix them before they ever affected the stable channel: Robert Swiecki; Google Security Team, Alexey Proskuryakov; Apple, Florian Rienhardt; BSI, and Ben Davis.
-DOWNLOAD-
Google Chrome 5.0.375.55
Google Chrome 5.0.375.55 has been released to the Stable channel for Linux, Mac and Windows.
For more details about the new features in the release, over our previous stable release 4.1, please see the Official Google Chrome blog.
Security Fixes:
Please see the Chromium security page for more detail. Note that the referenced bugs may be kept private until a majority of our users are up to date with the fix.
* [7713] Medium Canonicalize URLs closer to the Safe Browsing specification. Credit to Brett Wilson of the Chromium development community.
* [16535] High Possible URL bar spoofing via unload event handlers. Credit to Michal Zalewski, Google Security Team.
* [30079] Medium Memory error in Safe Browsing interaction. Credit to Google Chrome Security Team (SkyLined).
* [39740] Medium Bypass of whitelist-mode plugin blocker. Credit to Darin Fisher of the Chromium development community.
* [41469] Medium Memory error with drag + drop. Credit to kuzzcc.
* [42228] High Incorrect execution of Javascript in the extension context. Credit to Andrey Kosyakov of the Chromium development community.
In addition, we fixed a range of minor issues such as non-exploitable crashes, hangs and other annoyances. Credit to Sumit Gwalani; Google Security Team, sirdarckcat; Google Security Team, Google Chrome Security Team (Inferno), Carlos Ghan, WHK; elhacker.net, x41, Aki Helin; OUSPG, Jordi Chancel, kuzzcc, Robert Swiecki; Google Security Team, Tavis Ormandy; Google Security Team and Florent; Skyrecon Systems.
Also, we would like to extend our thanks to the following people who helped find bugs so we could fix them before they ever affected the stable channel: Robert Swiecki; Google Security Team, Alexey Proskuryakov; Apple, Florian Rienhardt; BSI, and Ben Davis.
-DOWNLOAD-
Google Chrome 5.0.375.55
Tags:
chrome,
google,
web browser
Wednesday, April 28, 2010
Google Chrome 4.1.249.1064
(2010.04.27)
Google Chrome 4.1.249.1064 has been released to the Stable channel on Windows.
This release fixes the following security issues:
* Google Chrome was not using the correct path for the Java plugin for Java Version 6 Update 20.
* 4.1.249.1059 was much slower on JavaScript benchmarks than 4.1.249.1045. (Issue 42158)
This release also fixes the following security issues:
Please see the Chromium security page for more detail. Note that the referenced bugs may be kept private until a majority of our users are up to date with the fix.
* [$1000] [40445] High Cross-origin bypass in Google URL (GURL). Credit: Jordi Chancel.
* [40487] High Memory corruption in HTML5 Media handling. Credit: David Bloom of Google Security Team.
* [$500] [42294] High Memory corruption in font handling. Credit: wushi of team509.
If you find issues, please let us know: http://code.google.com/p/chromium/issues/entry
-DOWNLOAD-
Google Chrome 4.1.249.1064
Google Chrome 4.1.249.1064 has been released to the Stable channel on Windows.
This release fixes the following security issues:
* Google Chrome was not using the correct path for the Java plugin for Java Version 6 Update 20.
* 4.1.249.1059 was much slower on JavaScript benchmarks than 4.1.249.1045. (Issue 42158)
This release also fixes the following security issues:
Please see the Chromium security page for more detail. Note that the referenced bugs may be kept private until a majority of our users are up to date with the fix.
* [$1000] [40445] High Cross-origin bypass in Google URL (GURL). Credit: Jordi Chancel.
* [40487] High Memory corruption in HTML5 Media handling. Credit: David Bloom of Google Security Team.
* [$500] [42294] High Memory corruption in font handling. Credit: wushi of team509.
If you find issues, please let us know: http://code.google.com/p/chromium/issues/entry
-DOWNLOAD-
Google Chrome 4.1.249.1064
Tags:
chrome,
google,
web browser
Subscribe to:
Posts (Atom)