Google heeft versie 39 van zijn webbrowser Chrome uitgebracht. Google Chrome is beschikbaar voor Windows, Linux en OS X. Er zijn ook versies voor Android en iOS, maar die volgen een iets ander release-schema. Nieuw in versie 39 is dat er voor OS X nu ook een 64-bit versie van de browser beschikbaar is. De release notes maken melding van diverse nieuwe apps en extension-api's, en en veranderingen die de stabiliteit en prestaties ten goede moeten komen. Verder zijn er weer een groot aantal voornamelijk kleine maar toch ook een paar ernstige beveiligingsproblemen verholpen.
Stable Channel Update
The Chrome team is delighted to announce the promotion of Chrome 39 to the stable channel for Windows, Mac and Linux. Chrome 39.0.2171.65 contains a number of fixes and improvements, including:A partial list of changes is available in the log.
- 64-bit support for Mac
- A number of new apps/extension APIs
- Lots of under the hood changes for stability and performance
Security Fixes and Rewards
This update includes 42 security fixes. Below, we highlight fixes that were either contributed by external researchers or particularly interesting. Please see the Chromium security page for more information.As usual, our ongoing internal security work was responsible for a wide range of fixes:
- [389734] High CVE-2014-7899: Address bar spoofing.
- [406868] High CVE-2014-7900: Use-after-free in pdfium.
- [413375] High CVE-2014-7901: Integer overflow in pdfium.
- [414504] High CVE-2014-7902: Use-after-free in pdfium.
- [414525] High CVE-2014-7903: Buffer overflow in pdfium.
- [418161] High CVE-2014-7904: Buffer overflow in Skia.
- [421817] High CVE-2014-7905: Flaw allowing navigation to intents that do not have the BROWSABLE category.
- [423030] High CVE-2014-7906: Use-after-free in pepper plugins.
- [423703] High CVE-2014-0574: Double-free in Flash.
- [424453] High CVE-2014-7907: Use-after-free in blink. NSFOCUS Security Team.
- [425980] High CVE-2014-7908: Integer overflow in media.
- [391001] Medium CVE-2014-7909: Uninitialized memory read in Skia.
- [433500] CVE-2014-7910: Various fixes from internal audits, fuzzing and other initiatives.