Stable updates
Stable and Beta Channel Updates
- Updated UI
- Form Autofill
- Syncing of extensions and Autofill data
- Increased speed and stability
More information on these and other changes in Chrome 6 can be found on the Google Chrome blog. Download Chrome today!
Security fixes and rewards:
Please see the Chromium security page for more detail. Note that the referenced bugs may be kept private until a majority of our users are up to date with the fix.
- [34414] Low Pop-up blocker bypass with blank frame target. Credit to Google Chrome Security Team (Inferno) and “ironfist99”.
- [37201] Medium URL bar visual spoofing with homographic sequences. Credit to Chris Weber of Casaba Security.
- [41654] Medium Apply more restrictions on setting clipboard content. Credit to Brook Novak.
- [45659] High Stale pointer with SVG filters. Credit to Tavis Ormandy of the Google Security Team.
- [45876] Medium Possible installed extension enumeration. Credit to Lostmon.
- [46750] [51846] Low Browser NULL crash with WebSockets. Credit to Google Chrome Security Team (SkyLined), Google Chrome Security Team (Justin Schuh) and Keith Campbell.
- [$1000] [50386] High Use-after-free in Notifications presenter. Credit to Sergey Glazunov.
- [50839] High Notification permissions memory corruption. Credit to Michal Zalewski of the Google Security Team and Google Chrome Security Team (SkyLined).
- [$1337] [51630] [51739] High Integer errors in WebSockets. Credit to Keith Campbell and Google Chrome Security Team (Cris Neckar).
- [$500] [51653] High Memory corruption with counter nodes. Credit to kuzzcc.
- [51727] Low Avoid storing excessive autocomplete entries. Credit to Google Chrome Security Team (Inferno).
- [52443] High Stale pointer in focus handling. Credit to VUPEN Vulnerability Research Team (VUPEN-SR-2010-249).
- [$1000] [52682] High Sandbox parameter deserialization error. Credit to Ashutosh Mehra and Vineet Batra of the Adobe Reader Sandbox Team.
- [$500] [53001] Medium Cross-origin image theft. Credit to Isaac Dawson.
This release also fixes [51070] (Windows kernel bug workaround; credit to Marc Schoenefeld), which was incorrectly declared fixed in version 5.0.375.127.
In addition, we would like to credit Google Chrome Security Team (Inferno), James Robinson (Chromium development community), Google Chrome Security Team (Cris Neckar), Aki Helin of OUSPG, Fred Akalin (Chromium development community), Anna Popivanova, “myusualnickname”, Michal Zalewski of the Google Security Team, kuzzcc and Aaron Boodman (Chromium development community) for finding bugs during the development cycle such that they never reached a stable build.
Google Chrome 5.0.375.127 has been released to the Stable Channel on Windows, Mac, and Linux
Google Chrome 5.0.375.127 has been released to the Stable Channel on Windows, Mac, and Linux.
Security fixes and rewards:
Please see the Chromium security page for more detail. Note that the referenced bugs may be kept private until a majority of our users are up to date with the fix.
Aside from the listed security bugs fixed in Chromium, we have also deployed a workaround for a critical vulnerability where the root cause lies in an external component. Credit and $1337 to Marc Schoenefeld for enabling us to work around another Windows kernel bug [51070].
- [$1337] [45400] Critical Memory corruption with file dialog. Credit to Sergey Glazunov.
- [$500] [49596] High Memory corruption with SVGs. Credit to wushi of team509.
- [$500] [49628] High Bad cast with text editing. Credit to wushi of team509.
- [$1000] [49964] High Possible address bar spoofing with history bug. Credit to Mike Taylor.
- [$2000] [50515] [51835] High Memory corruption in MIME type handling. Credit to Sergey Glazunov.
- [$1337] [50553] Critical Crash on shutdown due to notifications bug. Credit to Sergey Glazunov.
- [51146] Medium Stop omnibox autosuggest if the user might be about to type a password. Credit to Robert Hansen.
- [$1000] [51654] High Memory corruption with Ruby support. Credit to kuzzcc.
- [$1000] [51670] High Memory corruption with Geolocation support. Credit to kuzzcc.
Google Chrome 5.0.375.126 has been released to the Stable channel on Linux, Mac, and Windows
Google Chrome 5.0.375.125 has been released to the Stable channel on Linux, Mac, Windows, and Chrome Frame
Please see the Chromium security page for more detail. Note that the referenced bugs may be kept private until a majority of our users are up to date with the fix.
Aside from the listed security bugs fixed in Chromium, we have also deployed workarounds for two critical vulnerabilities where the root cause lies in external components. Credit and $1337 to Marc Schoenefeld for enabling us to work around a Windows kernel bug [48283]. Credit and $1337 to Simon Berry-Byrne for enabling us to work around a glibc bug [48733].
- [$500] [42736] Medium Memory contents disclosure in layout code. Credit to Michail Nikolaev.
- [$500] [43813] High Issue with large canvases. Credit to sp3x of SecurityReason.com.
- [$500] [47866] High Memory corruption in rendering code. Credit to Jose A. Vazquez.
- [$500] [48284] High Memory corruption in SVG handling. Credit to Aki Helin of OUSPG.
- [48597] Low Avoid hostname truncation and incorrect eliding. Credit to Google Chrome Security Team (Inferno).
If you find issues, please let us know: http://code.google.com/p/chromium/issues/entry
Google Chrome 5.0.375.99 has been released to the Stable channel on Linux, Mac, and Window
- [42396] Low OOB read with WebGL. Credit to Sergey Glazunov; Google Chrome Security Team (SkyLined).
- [42575] [42980] Medium Isolate sandboxed iframes more strongly. Credit to sirdarckcat of Google Security Team.
- [$500] [43488] High Memory corruption with invalid SVGs. Credit to Aki Hekin of OUSPG; wushi of team509.
- [$500] [44424] High Memory corruption in bidi algorithm. Credit to wushi of team509.
- [45164] Low Crash with invalid image. Credit to Jose A. Vazquez.
- [$1000] [45983] High Memory corruption with invalid PNG (libpng bug). Credit to Aki Helin of OUSPG.
- [$500] [46360] High Memory corruption in CSS style rendering. Credit to wushi of team509.
- [46575] Low Annoyance with print dialogs. Credit to Mats Ahlgren.
- [47056] Low Crash with modal dialogs. Credit to Aki Helin of OUSPG.
If you find issues, please let us know: http://code.google.com/p/chromium/issues/entry
Google Chrome 5.0.375.86 has been released to the Stable channel on Linux, Mac, and Windows
Google Chrome 5.0.375.86 has been released to the Stable channel on Linux, Mac, and Windows.
- [38105] Medium XSS via application/json response (regression). Credit to Ben Davis for original discovery and Emanuele Gentili for regression discovery.
- [43322] Medium Memory error in video handling. Credit to Mark Dowd under contract to Google Chrome Security Team.
- [43967] High Subresource displayed in omnibox loading. Credit to Michal Zalewski of Google Security Team.
- [45267] High Memory error in video handling. Credit to Google Chrome Security Team (Cris Neckar).
- [$500] [46126] High Stale pointer in x509-user-cert response. Credit to Rodrigo Marcos of SECFORCE.
Google Chrome 5.0.375.70 has been released to the Stable channel on Linux, Mac, and Windows
- [15766] Medium Cross-origin keystroke redirection. Credit to Michal Zalewski of Google Security Team.
- [$2000] [39985] High Cross-origin bypass in DOM methods. Credit to Sergey Glazunov.
- [$500] [42723] High Memory error in table layout. Credit to wushi of team509.
- [Linux only] [43304] High Linux sandbox escape. Credit to Mark Dowd under contract to Google Chrome Security Team.
- [43307] High Bitmap stale pointer. Credit to Mark Dowd under contract to Google Chrome Security Team.
- [43315] High Memory corruption in DOM node normalization. Credit to Mark Dowd under contract to Google Chrome Security Team.
- [43487] High Memory corruption in text transforms. Credit to wushi of team509.
- [43902] Medium XSS in innerHTML property of textarea. Credit to sirdarckcat of Google Security Team.
- [44740] High Memory corruption in font handling. Credit: Apple.
- [44868] High Geolocation events fire after document deletion. Credit to Google Chrome Security Team (Justin Schuh).
- [44955] High Memory corruption in rendering of list markers. Credit: Apple.
Stable Channel Update
Google Chrome 4.1.249.1064 has been released to the Stable channel on Windows
- Google Chrome was not using the correct path for the Java plugin for Java Version 6 Update 20.
- 4.1.249.1059 was much slower on JavaScript benchmarks than 4.1.249.1045. (Issue 42158)
- [$1000] [40445] High Cross-origin bypass in Google URL (GURL). Credit: Jordi Chancel.
- [40487] High Memory corruption in HTML5 Media handling. Credit: David Bloom of Google Security Team.
- [$500] [42294] High Memory corruption in font handling. Credit: wushi of team509.
Google Chrome 4.1.249.1059 has been released to the Stable channel on Windows
- [$500] [39443] High Type confusion error with forms. Credit: kuzzcc.
- [39698] High HTTP request error leading to possible XSRF. Credit: Meder Kydyraliev, Google Security Team.
- [40136] Medium Local file reference through developer tools. Credit: Robert Swiecki, Google Security Team; Tavis Ormandy, Google Security Team.
- [40137] Medium Cross-site scripting in chrome://net-internals. Credit: Robert Swiecki, Google Security Team; Tavis Ormandy, Google Security Team.
- [40138] High Cross-site scripting in chrome://downloads. Credit: Robert Swiecki, Google Security Team; Tavis Ormandy, Google Security Team.
- [40575] Medium Pages might load with privileges of the New Tab page.
- [$500] [40635] High Memory corruption in V8 bindings. Credit: kuzzcc; Google Chrome Security Team (SkyLined); Michal Zalewski, Google Security Team.
Google Chrome 4.1.249.1045 has been released to the Stable channel on Windows: Disable Translate
- Fix to prevent crashes with the LastPass extension (Issue 38857)
- Add the option to disable 'Offer to translate pages that aren't in a language I read' in Options > Under the Hood
- [38845] Low Crash with bad FTP response. Credit to Tobias Klein (www.trapkit.de).
Google Chrome 4.1.249.1042 has been released to the Windows Stable channel
Google Chrome 4.1.249.1042 has been released to the Windows Stable channel.
This release fixes an issue with some extensions not installing from the Google Chrome extensions gallery (issue 38220).
The stable channel has been updated to 4.1.249.1036 for Windows
The stable channel has been updated to 4.1.249.1036 for Windows, and includes the following features and security fixes (since 4.0):
- Translate infobar.
- Privacy features: content settings (cookies, images, JavaScript, plug-ins, pop-ups).
- Disabling experimental new anti-reflected-XSS feature called "XSS Auditor". The feature is still experimental, and we're disabling it while we look into some serious performance issues in rare cases. Please see this post for more details about what the XSS Auditor is.
Please see this feature announcment post for more info about translate and privacy.
Security Fixes and rewards:
Please see the Chromium security page for more detail. Note that the referenced bugs may be kept private until a majority of our users are up to date with the fix.
Congratulations to Sergey Glazunov on receiving the first $1337 Chromium Security Rewardforbug 35724.
- [28804] [31880] High Race conditions and pointer errors in the sandbox infrastructure.Credit to Mark Dowd, under contract to Google Chrome Security Team.
- [30801] [33445] Low Delete persisted metadata such as Web Databases and STS.Credit to Google Chrome Security Team (Chris Evans) and RSnake of ha.ckers.org.
- [33572] Medium HTTP headers processed before SafeBrowsing check.Credit to Mike Dougherty of dotSyntax, LLC.
- [$500] [34978] High Memory error with malformed SVG.Credit to wushi of team509.
- [$1337] [35724] High Integer overflows in WebKit JavaScript objects.Credit to Sergey Glazunov.
- [36772] Medium HTTP basic auth dialog URL truncation.Credit to Google Chrome Security Team (Inferno).
- [37007] Medium Bypass of download warning dialog.Credit to kuzzcc.
- [$1000] [37383] High Cross-origin bypass.Credit to kuzzcc.
- [$500] [Affected BETA only] [37061] High Memory error with empty SVG Credit to Aki Helin of OUSPG.
The stable channel has been updated to 4.0.249.89 for Windows
The stable channel has been updated to 4.0.249.89 for Windows.
Stable Channel Update
The stable channel has been updated to 4.0.249.78 for Windows, and includes the following features and security fixes (since 3.0):
Google Chrome Stable channel (Windows) has been updated to version 3.0.195.38
Google Chrome's Stable channel has been updated to version 3.0.195.38. (The Stable channel is still Windows-only.)
This release fixes a couple of browser crashes:
- r31694 fixes a crash while typing in the omnibox (issue 20511).
- r32474 fixes a crash while playing mp4 videos with odd sizes, such as 1366x768 (issue 27675).
Stable Update: Fix Google Chrome not Starting
Beta/Stable Channel Update
- Fixed an issue where menu items for certain Indian languages were not properly visible. (Issue: 18042)
- Add support to blacklist the faux www.paypal.com certificate. (Issue:24038)
Beta and Stable Channel Update
The beta and stable channels have been updated to 195.25. This release includes only a single change that adds an image link to the new tab page which directs new users to the themes gallery.
Anthony Laforge
Google Chrome Program Manager

