What's new in this version:
Google Chrome 42.0.2311.90
- A number of new apps, extension and Web Platform APIs (including the Push API!)
- Lots of under the hood changes for stability and performance
Google Chrome 41.0.2272.118
- Change log not available for this version.
Google Chrome 41.0.2272.101
- Change log not available for this version.
Google Chrome 41.0.2272.89
- Change log not available for this version.
Google Chrome 41.0.2272.76
- A number of new apps/extension APIs
- Lots of under the hood changes for stability and performance
- 51 security fixes
Google Chrome 40.0.2214.115
- Change log not available for this version.
Google Chrome 40.0.2214.111
- [447906] High CVE-2015-1209: Use-after-free in DOM.
- [453979] High CVE-2015-1210: Cross-origin-bypass in V8 bindings.
- [453982] High CVE-2015-1211: Privilege escalation using service workers.
- [455225] CVE-2015-1 212: Var ious fixes from internal audits, fuzzing and other initiatives.
Google Chrome 40.0.2214.94
- Handle invalid sync item ordinals when adding OEM folders. Certain edge cases were exposing a lack of proper checking for validity when handling sync ordinals.
Google Chrome 40.0.2214.91
- Updated info dialog for Chrome app on Windows and Linux
- A new clock behind/ahead error message
Google Chrome 39.0.2171.99
- This release contains an update for Adobe Flash as well as a number of other fixes.
Google Chrome 39.0.2171.95
- Change log not available for this version.
Google Chrome 39.0.2171.71
- Contains an update for Adobe Flash
- A number of other fixes
Google Chrome 39.0.2171.65
- A number of new apps/extension APIs
- Lots of under-the-hood changes for stability and performance
Google Chrome 38.0.2125.122
- Contains an update for Adobe Flash as well as a n umber of other fixes
Google Chrome 38.0.2125.111
- Change log not available for this version.
Google Chrome 38.0.2125.104
- Contains an update for Adobe Flash as well as a number of other fixes
Google Chrome 38.0.2125.101
- A number of new apps/extension APIs
- Lots of under the hood changes for stability and performance
- A special thanks to Jüri Aedla for a combination of V8 and IPC bugs that can lead to remote code execution outside of the sandbox.
- Out-of-bounds read in PDFium.
- Use-after-free in Events.
- Use-after-free in Rendering.
- Use-after-free in DOM.
- Type confusion in Session Management.
- Use-after-free in Web Workers.
- Information Leak in V8.
- Permissions bypass in Windows Sandbox.
- Information Leak in XSS Auditor.
- Out-of-bounds read in PDFium.
- Release Assert in V8 bindings. Google Chrome 37.0.2062.124
- RSA signature malleability in NS S
< br />Google Chrome 37.0.2062.124
- RSA signature malleability in NSS
Google Chrome 37.0.2062.120
- This release contains an update for Adobe Flash and includes 4 security fixes. Below, we highlight fixes that were either contributed by external researchers or particularly interesting:
- Use-after-free in rendering.
- Various fixes from internal audits, fuzzing and other initiatives.
Google Chrome 37.0.2062.103
- This addresses some user feedback related to how Chrome renders text when display scaling is set to 125% or lower.
Google Chrome 37.0.2062.102
- Change log not available for this version.
Google Chrome 37.0.2062.94
- DirectWrite support on Windows for improved font rendering
- A number of new apps/extension APIs
- Lots of under the hood changes for stability and performance Security Fixes:
- Critical CVE-2014-3176, CVE-2014-3177: A special reward to lokihardt@asrt for a com bination of bugs in V8, IPC, sync, and extensions that can lead to remote code execution outside of the sandbox.
- High CVE-2014-3168: Use-after-free in SVG.
- High CVE-2014-3169: Use-after-free in DOM.
- High CVE-2014-3170: Extension permission dialog spoofing.
- High CVE-2014-3171: Use-after-free in bindings.
- Medium CVE-2014-3172: Issue related to extension debugging.
- Medium CVE-2014-3173: Uninitialized memory read in WebGL.
- Medium CVE-2014-3174: Uninitialized memory read in Web Audio.
- CVE-2014-3175: Various fixes from internal audits, fuzzing and other initiatives (Chrome 37). Google Chrome 36.0.1985.143
- Use-after-free in web sockets.
- Information disclosure in SPDY.
- Various fixes from internal audits, fuzzing and other initiatives.
Google Chrome 36.0.1985.125
- Rich Notifications Improvements
- An Updated Incognito / Guest NTP design
- The addition of a Browser crash recovery bubble
- Chro me App Launcher for Linux
- Lots of under the hood changes for stability and performance Security Fixes:
- Medium CVE-2014-3160: Same-Origin-Policy bypass in SVG
- CVE-2014-3162: Various fixes from internal audits, fuzzing and other initiatives.
Google Chrome 35.0.1916.153
This update includes 4 security fixes:
- CVE-2014-3154: Use-after-free in filesystem API.
- CVE-2014-3155: Out-of-bounds read in SPDY.
- CVE-2014-3156: Buffer overflow in clipboard.
- CVE-2014-3157: Heap overflow in media. Google Chrome 35.0.1916.114
- More developer control over touch input
- New JavaScript features
- Unprefixed Shadow DOM
- A number of new apps/extension APIs
- Lots of under the hood changes for stability and performance
- This update includes 23 security fixes
Google Chrome 34.0.1847.137
- Use-after-free in WebSockets.
- Integer overflow in DOM ranges.
- Use-after-free in editin g. Googl e Chrome 34.0.1847.131
- This release fixes a number of crashes and other bugs.
- Contains a Flash Player update, to version 13.0.0.214
Google Chrome 34.0.1847.116
- Responsive Images and Unprefixed Web Audio
- Import supervised users onto new computers
- A number of new apps/extension APIs
- A different look for Win8 Metro mode
- Lots of under the hood changes for stability and performance
Google Chrome 33.0.1750.154
- Code execution outside sandbox. Credit to VUPEN.
- Use-after-free in Blink bindings
- Code execution outside sandbox. Credit to Anonymous.
- Memory corruption in V8
- Directory traversal issue
Google Chrome 33.0.1750.149
- Use-after-free in speech.
- UXSS in events.
- Use-after-free in web database. As usual, our ongoing internal security work responsible for a wide range of fixes:
- Potential sandbox escape due to a use-after-free in web sockets.< br />- M ultiple vulnerabilities in V8 fixed in version 3.23.17.18.
Google Chrome 33.0.1750.146
- Use-after-free in svg images.
- Use-after-free in speech recognition. .
- Heap buffer overflow in software rendering.
- Chrome allows requests in flash header request. As usual, our ongoing internal security work responsible for a wide range of fixes:
- Various fixes from internal audits, fuzzing and other initiatives.
- Multiple vulnerabilities in V8 fixed in version 3.24.35.10.
Google Chrome Google Chrome 33.0.1750.117
- Issue with relative paths in Windows sandbox named pipe policy. Credit to tyranid.
- Use-after-free related to web contents. Credit to Khalil Zhani.
- Bad cast in SVG. Credit to TheShow3511.
- Use-after-free in layout. Credit to cloudfuzzer.
- Information leak in XSS auditor. Credit to NeexEmil.
- Information leak in XSS auditor. Credit to NeexEmil.
- Use-after-free in layout. Credi t to clo udfuzzer.
- Issue with certificates validation in TLS handshake. Credit to Antoine Delignat-Lavaud and Karthikeyan Bhargavan from Prosecco, Inria Paris.
- Information leak in drag and drop. Credit to bishopjeffreys.
- Various fixes from internal audits, fuzzing and other initiatives. Of these, seven are fixes for issues that could have allowed for sandbox escapes from compromised renderers.
Google Chrome 32.0.1700.107
- Change log not available for this version
Google Chrome 32.0.1700.102
- Mouse Pointer disappears after exiting full-screen mode.
- Drag and drop files into Chrome may not work properly.
- Quicktime Plugin crashes in Chrome.
- Chrome becomes unresponsive.
- Trackpad users may not be able to scroll horizontally.
- Scrolling does not work in combo box.
- Chrome does not work with all CSS minifiers such as whitespace around a media query's `and` keyword.
- This update includes 14 s ecurity fixes.
Google Chrome 32.0.1700.76
- Tab indicators for sound, webcam and casting
- A different look for Win8 Metro mode
- Automatically blocking malware files
- A number of new apps/extension APIs
- Lots of under the hood changes for stability and performance
- Flash Player has been updated to version 12.0.0.41
- This update includes 11 security fixes
Google Chrome 31.0.1650.63
- Session fixation in sync related to 302 redirects.
- Use-after-free in editing.
- Address bar spoofing related to modal dialogs.
- Various fixes from internal audits, fuzzing and other initiatives.
- Buffer overflow in v8. This issue was fixed in v8 version 3.22.24.7.
- Out of bounds write in v8. This issue was fixed in v8 version 3.22.24.7.
- Out of bounds read in v8. This issue was fixed in v8 version 3.22.24.7.
Google Chrome 31.0.1650.57
- Fixed multiple memory corruption issues.
No comments:
Post a Comment