Google heeft versie 43 van zijn webbrowser Chrome uitgebracht. Google Chrome is beschikbaar voor Windows, Linux en OS X. Er zijn ook versies voor Android en iOS, maar die volgen een iets ander release-schema. In versie 43 treffen we geen nieuwe mogelijkheden aan. Wel zijn er verschillende foutjes en 37 beveiligingsproblemen verholpen. De releasenotes voor deze uitgave zien er als volgt uit:
Stable Channel Update
The Chrome team is happy to announce the promotion of Chrome 43 to the stable channel for Windows, Mac and Linux. Chrome 43.0.2357.65 contains a number of fixes and improvements. A list of changes is available in the log.
Security Fixes and Rewards
Note: Access to bug details and links may be kept restricted until a majority of users are updated with a fix. We will also retain restrictions if the bug exists in a third party library that other projects similarly depend on, but haven’t yet fixed.
This update includes 37 security fixes. Below, we highlight fixes that were contributed by external researchers. Please see the Chromium security page for more information.As usual, our ongoing internal security work was responsible for a wide range of fixes:
- [474029] High CVE-2015-1252: Sandbox escape in Chrome.
- [464552] High CVE-2015-1253: Cross-origin bypass in DOM.
- [444927] High CVE-2015-1254: Cross-origin bypass in Editing.
- [473253] High CVE-2015-1255: Use-after-free in WebAudio.
- [478549] High CVE-2015-1256: Use-after-free in SVG.
- [481015] High CVE-2015-1251: Use-after-free in Speech.
- [468519] Medium CVE-2015-1257: Container-overflow in SVG.
- [450939] Medium CVE-2015-1258: Negative-size parameter in Libvpx.
- [468167] Medium CVE-2015-1259: Uninitialized value in PDFium.
- [474370] Medium CVE-2015-1260: Use-after-free in WebRTC.
- [466351] Medium CVE-2015-1261: URL bar spoofing.
- [476647] Medium CVE-2015-1262: Uninitialized value in Blink.
- [479162] Low CVE-2015-1263: Insecure download of spellcheck dictionary.
- [481015] Low CVE-2015-1264: Cross-site scripting in bookmarks.
- [489518] CVE-2015-1265: Various fixes from internal audits, fuzzing and other initiatives.
- Multiple vulnerabilities in V8 fixed at the tip of the 4.3 branch (currently 4.3.61.21).