Home

Google Chrome Browser

making the web faster, safer, and easier

Main menu

  • Home
  • Chromebook
  • Chrome OS
  • Books
  • Releases
    • Stable
    • Beta channel
    • Dev channel
  • Downloads
  • Videos
    • Top Rated
    • Most Viewed
    • Most Commented
  • Articles
    • Top Rated
    • Most Viewed
    • Most Commented
  • About Us
Home

Add to Technorati Favorites

Subscribe to Google Chrome Browser by e-mail

Delivered by FeedBurner

Syndicate

Syndicate content

User login

Login/Register
What is OpenID?
  • Log in using OpenID
  • Cancel OpenID login
  • Create new account
  • Request new password

Tag Cloud

Beta updates browser browsers browsing chrome chrome extensions Chrome OS chromium Dev updates Downloads extension extensions feed Firefox Google google chrome googlechrome Linux News opera release safari security Stable updates TC video web web browser web browsers windows
more tags

Twitter Updates

Follow us on Twitter @ChromeBrowser


    Stable Channel Update

    • View
    • Track
    Submitted by admin on Thu, 11/05/2009 - 16:18
    • release
    • Stable updates


    The stable channel has been updated to 3.0.195.32, and includes the following security and stability fixes:
    • Resolved a history issue that affected going back from queries in Google Maps. (Issue: 21353)
    • Fixed issue with Adobe Acrobat Reader 9.2, where no content would be displayed. (Issue: 24883)
    • Fixed an infinite loop in AAC decoding. (Webkit Issue: 27239)
    • Fixed a top crasher. (Issue: 22205)
    • Fix issues where setInterval sometimes eats 100% CPU. (Issue: 25892)

    Security Fixes:

    CVE-2009-XXXX User not warned for some file types that can execute JavaScript


    The user was not warned about certain possibly dangerous file types such as SVG, MHT and XML files. In some browsers, JavaScript can execute within these types of files. Because the JavaScript runs in the local context, it may be able to access local resources.


    More info: http://code.google.com/p/chromium/issues/detail?id=23979
    (This issue will be made public once a majority of users are up to date with the fix.)

    Severity: Medium
    Credit: Inferno of SecureThoughts.com
    Mitigations:



    • A victim would need to visit a page under an attacker's control.
    • The victim would furthermore need to open a malicious file.



    CVE-2009-XXXX Possible memory corruption in the Gears plugin


    A malicious site could use the Gears SQL API to put SQL metadata into a bad state, which could cause a subsequent memory corruption. This may lead to a Gears plugin crash or possibly arbitrary code execution.


    More info: http://code.google.com/p/chromium/issues/detail?id=26179
    (This issue will be made public once a majority of users are up to date with the fix.)

    Severity: High
    Credit: This issue was found by the Google Chrome security team.
    Mitigations:



    • A victim would need to visit a page under an attacker's control.
    • The victim would furthermore need to "click-through" the Gears dialog confirming that they trust the attacker's evil page.

    Anthony Laforge
    Google Chrome Program Manager

    No votes yet
    • 354 reads
    • Feed: Google Chrome Releases
    • Original article

    Post new comment

    • Web page addresses and e-mail addresses turn into links automatically.
    • Allowed HTML tags: <a> <em> <strong> <cite> <code> <ul> <ol> <li> <dl> <dt> <dd>
    • Lines and paragraphs break automatically.
    • E-Mail addresses are hidden with reCAPTCHA Mailhide.
    • You may insert videos with [video:URL]

    More information about formatting options

    CAPTCHA
    This question is for testing whether you are a human visitor and to prevent automated spam submissions.

    Google Chrome Browser is a community site for users and developers of the Google Chrome browser.
    Google™ is a Trademark of Google Inc. All other company and product names may be trademarks of the respective companies with which they are associated.
    Google Chrome Browser site is not affiliated with or sponsored by Google Inc.
    Google Chrome Browser site is built on the Drupal open source content management system.