Google heeft een update voor versie 17 van zijn webbrowser Chrome uitgebracht. Google Chrome is beschikbaar in drie verschillende uitvoeringen: stable, bèta en dev. Developmentversies zitten in een vroeg stadium van ontwikkeling en zijn dus het minst stabiel. In versie 17 is onder andere de omnibox verbeterd. Terwijl je nog bezig bent de zoekterm in te tikken haalt Google alvast de pagina op die het denkt dat je wilt zien. Verder worden nu ook downloads tegen het licht gehouden om zo de gebruiker beter te beschermen. Deze update bevat diverse verbeteringen met betrekking tot Flash-spelletjes en problemen die in de Pwn2Own-wedstrijd naar voren zijn gekomen.
Stable Channel Update
The Chrome Stable channel has been updated to 17.0.963.83 on Windows, Mac, Linux and Chrome Frame. This release fixes issues with Flash games, along with the security fixes listed below.
Security fixes and rewards:
Please see the Chromium security page for more detail. Note that the referenced bugs may be kept private until a majority of our users are up to date with the fix.
Some of the items listed below represent the start of hardening measures based on study of the exploits submitted to the Pwnium competition.Also, this single low severity issue was fixed in a previous patch but we forgot to issue proper credit:
- [113902] High CVE-2011-3050: Use-after-free with first-letter handling.
- [116162] High CVE-2011-3045: libpng integer issue from upstream.
- [116461] High CVE-2011-3051: Use-after-free in CSS cross-fade handling.
- [116637] High CVE-2011-3052: Memory corruption in WebGL canvas handling.
- [116746] High CVE-2011-3053: Use-after-free in block splitting.
- [117418] Low CVE-2011-3054: Apply additional isolations to webui privileges.
- [117736] Low CVE-2011-3055: Prompt in the browser native UI for unpacked extension installation.
- [117550] High CVE-2011-3056: Cross-origin violation with “magic iframe”.
- [117794] Medium CVE-2011-3057: Invalid read in v8.
More detailed updates are available on the Chrome Blog. Full details about what changes are in this release are available in the SVN revision log. Interested in hopping on the stable channel? Find out how. If you find a new issue, please let us know by filing a bug.
- Low CVE-2011-3049: Extension web request API can interfere with system requests.