Home

Google Chrome Browser

making the web faster, safer, and easier

Main menu

  • Home
  • Chromebook
  • Chrome OS
  • Android
  • Books
  • Releases
    • Stable
    • Beta channel
    • Dev channel
  • Downloads
  • Videos
    • Top Rated
    • Most Viewed
    • Most Commented
  • Articles
    • Top Rated
    • Most Viewed
    • Most Commented
  • About Us
Home

Add to Technorati Favorites

Subscribe to Google Chrome Browser by e-mail

Delivered by FeedBurner

Syndicate

Syndicate content

User login

Login/Register
What is OpenID?
  • Log in using OpenID
  • Cancel OpenID login
  • Create new account
  • Request new password

Tag Cloud

Beta updates browser browsers browsing chrome chromebook chrome extensions Chrome OS chromium Dev updates Downloads extensions feed Firefox Google googlechrome google chrome Internet Explorer Linux open source opera release security Stable updates TC video web web browser web browsers windows
more tags

Twitter Updates

Follow us on Twitter @ChromeBrowser


    Stable Channel Update

    • View
    • Track
    Submitted by admin on Tue, 09/15/2009 - 11:59
    • release
    • Stable updates

     

    3.0.195.21 has graduated from Beta to the Stable channel today.

    This release includes themes support, a brand new New Tab page, an updated omnibox, support for audio and video tags, and a higher performing V8 engine.

    You can read more about it here.

    Anthony Laforge
    Google Chrome Program Manager


    Security Fixes:

    We would like to extend special thanks to Will Dormann of CERT for working with us to improve the security of the new audio and video codecs in this release.

    CVE-2009-XXXX  Content-Type: application/rss+xml being rendered as active content

    Previously, we rendered RSS and Atom feeds as XML.  Because most other browsers render these documents with dedicated feed previewers, some web sites do not sanitize their feeds for active content, such as
    JavaScript.  In these cases, an attacker might be able to inject JavaScript into a target web site.

    More info: http://code.google.com/p/chromium/issues/detail?id=21238
    (This issue will be made public once a majority of users are up to date with the fix.)

    Severity: Medium.  Most web sites are not affected because they do not include untrusted content in RSS or Atom feeds.

    Credit: Inferno of SecureThoughts.com


    Mitigations:
    • A victim would need to visit a page under an attacker's control.
    • The target web site would need to let the attacker inject JavaScript into an RSS or an Atom feed.

    CVE-2009-XXXX  Same Origin Policy Bypass via getSVGDocument() method

    The getSVGDocument method was lacking an access check, resulting in a cross-origin JavaScript capability leak.  A malicious web site operator could use the leaked capability to inject JavaScript into a target web site hosting an SVG document, bypassing the same-origin policy.

    More info: http://code.google.com/p/chromium/issues/detail?id=21338
    (This issue will be made public once a majority of users are up to date with the fix.)

    Severity: High

    Credit: Isaac Dawson


    Mitigations:
    • A victim would need to visit a page under an attacker's control.
    • The target web site would need to host an SVG document.

    Google Chrome (Stable) 3.0.195.21 Offline Windows Installer
    No votes yet
    • 659 reads
    • Feed: Google Chrome Releases
    • Original article

    Post new comment

    • Web page addresses and e-mail addresses turn into links automatically.
    • Allowed HTML tags: <a> <em> <strong> <cite> <code> <ul> <ol> <li> <dl> <dt> <dd>
    • Lines and paragraphs break automatically.
    • E-Mail addresses are hidden with reCAPTCHA Mailhide.
    • You may insert videos with [video:URL]

    More information about formatting options

    CAPTCHA
    This question is for testing whether you are a human visitor and to prevent automated spam submissions.

    Google Chrome Browser is a community site for users and developers of the Google Chrome browser.
    Google™ is a Trademark of Google Inc. All other company and product names may be trademarks of the respective companies with which they are associated.
    Google Chrome Browser site is not affiliated with or sponsored by Google Inc.
    Google Chrome Browser site is built on the Drupal open source content management system.