Google heeft versie 34 van zijn webbrowser Chrome uitgebracht. Google Chrome is beschikbaar in drie uitvoeringen: stable, beta en dev, en ditmaal is de stabiele uitvoering bijgewerkt. Nieuw in versie 34 is onder meer ondersteuning voor flexibele afbeeldingen en unprefixed Web Audio. Verder ziet Chrome er iets anders uit in de modern UI van Windows 8 en zijn er ook weer een heleboel bugfixes doorgevoerd en beveiligingsproblemen verholpen. De complete release notes voor deze uitgave kunnen hieronder worden gevonden.
Stable Channel Update
The Chrome Team is excited to announce the promotion of Chrome 34 to the Stable channel for Windows, Mac, and Linux. Chrome 34.0.1847.116 contains a number of fixes and improvements, including:You can read more about these changes at the Chrome blog.
- Responsive Images and Unprefixed Web Audio
- Import supervised users onto new computers
- A number of new apps/extension APIs
- A different look for Win8 Metro mode
- Lots of under the hood changes for stability and performance
Flash Player has been updated to 13.0.0.182, which is included w/ this release.
Security Fixes and Rewards
This update includes 31 security fixes. Below, we highlight fixes that were either contributed by external researchers or particularly interesting. Please see the Chromium security page for more information.
[354123] High CVE-2014-1716: UXSS in V8.
[353004] High CVE-2014-1717: OOB access in V8.
[348332] High CVE-2014-1718: Integer overflow in compositor.
[343661] High CVE-2014-1719: Use-after-free in web workers.
[356095] High CVE-2014-1720: Use-after-free in DOM.
[350434] High CVE-2014-1721: Memory corruption in V8.
[330626] High CVE-2014-1722: Use-after-free in rendering.
[337746] High CVE-2014-1723: Url confusion with RTL characters.
[327295] High CVE-2014-1724: Use-after-free in speech.
[357332] Medium CVE-2014-1725: OOB read with window property.
[346135] Medium CVE-2014-1726: Local cross-origin bypass.
[342735] Medium CVE-2014-1727: Use-after-free in forms.
As usual, our ongoing internal security work responsible for a wide range of fixes:Many of the above bugs were detected using AddressSanitizer.
- [360298] CVE-2014-1728: Various fixes from internal audits, fuzzing and other initiatives.
- [345820, 347262, 348319, 350863, 352982, 355586, 358059] CVE-2014-1729: Multiple vulnerabilities in V8 fixed in version 3.24.35.22.
As we’ve previously discussed, Chrome will now offer to remember and fill password fields in the presence of autocomplete=off. This gives more power to users in spirit of the priority of constituencies, and it encourages the use of the Chrome password manager so users can have more complex passwords. This change does not affect non-password fields.
A partial list of changes is available in the SVN log. Interested in switching release channels? Find out how. If you find a new issue, please let us know by filing a bug.