Google heeft versie 41 van zijn webbrowser Chrome uitgebracht. Google Chrome is beschikbaar voor Windows, Linux en OS X. Er zijn ook versies voor Android en iOS, maar die volgen een iets ander release-schema. In versie 41 treffen we onder meer diverse nieuwe app- en extention-api's aan en zijn er maar liefst 51 beveiligingsproblemen verholpen.
Stable Channel Update
The Chrome team is delighted to announce the promotion of Chrome 41 to the stable channel for Windows, Mac and Linux. Chrome 41.0.2272.76 contains a number of fixes and improvements, including:A list of changes is available in the log.
- A number of new apps/extension APIs
- Lots of under the hood changes for stability and performance
Security Fixes and Rewards
Note: Access to bug details and links may be kept restricted until a majority of users are updated with a fix. We will also retain restrictions if the bug exists in a third party library that other projects similarly depend on, but haven’t yet fixed.
This update includes 51 security fixes. Below, we highlight fixes that were contributed by external researchers. Please see the Chromium security page for more information.We would also like to thank all security researchers that worked with us during the development cycle to prevent security bugs from ever reaching the stable channel. The total value of additional rewards and their recipients will be updated here when all reports have gone through the reward panel.
- [456516] High CVE-2015-1212: Out-of-bounds write in media.
- [448423] High CVE-2015-1213: Out-of-bounds write in skia filters.
- [445810] High CVE-2015-1214: Out-of-bounds write in skia filters.
- [445809] High CVE-2015-1215: Out-of-bounds write in skia filters.
- [454954] High CVE-2015-1216: Use-after-free in v8 bindings.
- [456192] High CVE-2015-1217: Type confusion in v8 bindings.
- [456059] High CVE-2015-1218: Use-after-free in dom.
- [446164] High CVE-2015-1219: Integer overflow in webgl.
- [437651] High CVE-2015-1220: Use-after-free in gif decoder.
- [455368] High CVE-2015-1221: Use-after-free in web databases.
- [448082] High CVE-2015-1222: Use-after-free in service workers.
- [454231] High CVE-2015-1223: Use-after-free in dom.
- [449610] High CVE-2015-1230: Type confusion in v8.
- [449958] Medium CVE-2015-1224: Out-of-bounds read in vpxdecoder.
- [446033] Medium CVE-2015-1225: Out-of-bounds read in pdfium.
- [456841] Medium CVE-2015-1226: Validation issue in debugger.
- [450389] Medium CVE-2015-1227: Uninitialized value in blink.
- [444707] Medium CVE-2015-1228: Uninitialized value in rendering.
- [431504] Medium CVE-2015-1229: Cookie injection via proxies.
As usual, our ongoing internal security work was responsible for a wide range of fixes:
- [463349] CVE-2015-1231: Various fixes from internal audits, fuzzing and other initiatives.
- Multiple vulnerabilities in V8 fixed at the tip of the 4.1 branch (currently 4.1.0.21).