Google heeft een update voor versie 27 van zijn webbrowser Chrome uitgebracht. Google Chrome is beschikbaar in drie verschillende uitvoeringen: stable, beta en dev, en ditmaal is de stabiele uitvoering bijgewerkt. Nieuw in versie 27 is de chrome.syncFileSystem-api, waarmee apps de mogelijkheid krijgen specifieke data op Google Drive op te slaan, zodat deze op verschillende clients en platforms beschikbaar zijn. Verder laden pagina's gemiddeld vijf procent sneller en zijn er verbeteringen aan de spellingscontrole en Omnibox aangebracht. Daarnaast zijn er natuurlijk weer de nodige beveiligingsupdates en bugfixes doorgevoerd. Het changelog voor deze update laat verder alleen beveiligingsupdates zien.
Security fixes and rewards:
Please see the Chromium security page for more information. (Note that the referenced bugs may be kept private until a majority of our users are up to date with the fix.)
This automatic update includes security fixes. We’d like to highlight the following fixes for various reasons (crediting external researchers, issuing rewards, or highlighting particularly interesting issues):In addition, our ongoing internal security work was as usual responsible for a wide range of fixes:
- [Windows only] [243339] High CVE-2013-2854: Bad handle passed to renderer.
- [242322] Medium CVE-2013-2855: Memory corruption in dev tools API.
- [242224] High CVE-2013-2856: Use-after-free in input handling.
- [240124] High CVE-2013-2857: Use-after-free in image handling.
- [239897] High CVE-2013-2858: Use-after-free in HTML5 Audio.
- [237022] High CVE-2013-2859: Cross-origin namespace pollution.
- [225546] High CVE-2013-2860: Use-after-free with workers accessing database APIs.
- [209604] High CVE-2013-2861: Use-after-free with SVG.
- [161077] High CVE-2013-2862: Memory corruption in Skia GPU handling.
- [232633] Critical CVE-2013-2863: Memory corruption in SSL socket handling.
- [239134] High CVE-2013-2864: Bad free in PDF viewer.
Full details about what changes are in this build are available in the SVN revision log. Interested in switching release channels? Find out how. If you find a new issue, please let us know by filing a bug.
- [246389] High CVE-2013-2865: Various fixes from internal audits, fuzzing and other initiatives.