Stable updates
Stable Update - The Stable channel has been updated to 13.0.782.218 for Windows, Mac, Linux, and Chrome Frame
The Stable channel has also been updated to 13.0.782.218 for Windows, Mac, Linux, and Chrome Frame.
These releases contain an updated version of the Adobe Flash Player.
Stable Channel Update for Chromebooks - release of Chrome 13.0.782.216 for Chromebooks (Acer AC700, Samsung Series 5, and Cr-48)
The Google Chrome team is happy to announce the release of Chrome 13.0.782.216 (Platform version: 587.126) on the Stable Channel for Chromebooks (Acer AC700, Samsung Series 5, and Cr-48).
Highlights:
- Several Chrome security fixes. See blog post for details.
If you find new issues, please let us know by visiting our help site or filing a bug. You can also submit feedback using "Report an issue" under the wrench icon.
Stable Channel Update - The Chrome Stable channel has been updated to 13.0.782.215 for all platforms
Security fixes and rewards:
Please see the Chromium security page for more detail. Note that the referenced bugs may be kept private until a majority of our users are up to date with the fix.
- [$1000] [Windows only] [72492] Medium CVE-2011-2822: URL parsing confusion on the command line. Credit to Vladimir Vorontsov, ONsec company.
- [82552] High CVE-2011-2823: Use-after-free in line box handling. Credit to Google Chrome Security Team (SkyLined) and independent later discovery by miaubiz.
- [$1000] [88216] High CVE-2011-2824: Use-after-free with counter nodes. Credit to miaubiz.
- [88670] High CVE-2011-2825: Use-after-free with custom fonts. Credit to wushi of team509 reported through ZDI (ZDI-CAN-1283), plus indepdendent later discovery by miaubiz.
- [$1000] [89402] High CVE-2011-2821: Double free in libxml XPath handling. Credit to Yang Dingning from NCNIPC, Graduate University of Chinese Academy of Sciences.
- [$1000] [87453] High CVE-2011-2826: Cross-origin violation with empty origins. Credit to Sergey Glazunov.
- [$1337] [Windows only] [89836] Critical CVE-2011-2806: Memory corruption in vertex handing. Credit to Michael Braithwaite of Turbulenz Limited.
- [$1000] [90668] High CVE-2011-2827: Use-after-free in text searching. Credit to miaubiz.
- [91517] High CVE-2011-2828: Out-of-bounds write in v8. Credit to Google Chrome Security Team (SkyLined).
- [$1500] [32-bit only] [91598] High CVE-2011-2829: Integer overflow in uniform arrays. Credit to Sergey Glazunov.
- [$1000] [Linux only] [91665] High CVE-2011-2839: Buggy memset() in PDF. Credit to Aki Helin of OUSPG.
The full list of changes is available in the SVN revision log. Interested in switching to another? Find out how. If you find a new issue, please let us know by filing a bug.
Beta and Stable Channel Update - The Chrome Beta and Stable channels have been updated to 13.0.782.112 with updated version of Flash Player
The Chrome Beta and Stable channels have been updated to 13.0.782.112 which includes an updated version of Flash Player.
The Chrome Team would especially like to thank Tavis Ormandy, the Google Security Team, and Google for donating a large amount of time and compute power to identify a significant number of vulnerabilities resolved in this release of Flash Player.
Stable Channel Updates for Chromebooks
The Google Chrome team is happy to announce the release of Chrome 13 on the Stable Channel for Chromebooks (Acer AC700, Samsung Series 5, and Cr-48).
Chrome version 13.0.782.108 (Platform version 587.100)
Release highlights:
- Supports new Chrome 13 functionality (check out the
Official Chrome Blog for more information) - Google Cloud Print settings added to Settings > Under the Hood
- Allow auto-connect using 3G
- Remove/forget added VPN connections
- L2TP IPSec with pre-shared key support
- More SSH options in crosh
- 802.1x support
- Allow USB mounting of Android
- Crash fixes
- Security updates
Chrome OS Stable Channel Update - The Chrome OS Stable channel has been updated to R12 release 0.12.433.257
Beta and Stable Channel Update - The Stable channel has been updated to 12.0.742.122 for Windows, Mac and Chrome Frame; and 12.0.742.124 for Linux
The Stable channel has been updated to 12.0.742.122 for Windows, Mac and Chrome Frame; and 12.0.742.124 for Linux.
The Beta channel has also been updated to 13.0.782.55 for Windows, Mac and Chrome Frame; and 13.0.782.56 for Linux.
These releases contain an updated version of the Adobe Flash Player.
Chrome OS Stable Channel Update - The Chrome OS Stable channel has been updated to R12 release 0.12.433.231
- New localization
- Flash 10.2.158.27
- Power Management optimization
- Audio fixes
You can find full list of fixes that are in Chrome OS R12 in the chromium-os bug tracker. If you find new issues, please let us know by visiting our help site or filing a bug. You can submit feedback using ‘Report an issue’ under the wrench menu.
Stable Channel Update
Please see the Chromium security page for more detail. Note that the referenced bugs may be kept private until a majority of our users are up to date with the fix.
- [$1000] [77493] Medium CVE-2011-2345: Out-of-bounds read in NPAPI string handling. Credit to Philippe Arteau.
- [$1000] [84355] High CVE-2011-2346: Use-after-free in SVG font handling. Credit to miaubiz.
- [$1000] [85003] High CVE-2011-2347: Memory corruption in CSS parsing. Credit to miaubiz.
- [$500] [85102] High CVE-2011-2350: Lifetime and re-entrancy issues in the HTML parser. Credit to miaubiz.
- [$500] [85177] High CVE-2011-2348: Bad bounds check in v8. Credit to Aki Helin of OUSPG.
- [$1000] [85211] High CVE-2011-2351: Use-after-free with SVG use element. Credit to miaubiz.
- [$1000] [85418] High CVE-2011-2349: Use-after-free in text selection. Credit to miaubiz.
Stable, Beta Channel Updates - The Chrome Stable and Beta channels have been updated to 12.0.742.100 for all platforms
Chrome Stable Release
- Hardware accelerated 3D CSS
- New Safe Browsing protection against downloading malicious files
- Ability to delete Flash cookies from inside Chrome
- Launch Apps by name from the Omnibox
- Integrated Sync into new settings pages
- Improved screen reader support
- New warning when hitting Command-Q on Mac
- Removal of Google Gears
Security fixes and rewards:
Please see the Chromium security page for more detail. Note that the referenced bugs may be kept private until a majority of our users are up to date with the fix.
- [$2000] [73962] [79746] High CVE-2011-1808: Use-after-free due to integer issues in float handling. Credit to miaubiz.
- [75496] Medium CVE-2011-1809: Use-after-free in accessibility support. Credit to Google Chrome Security Team (SkyLined).
- [75643] Low CVE-2011-1810: Visit history information leak in CSS. Credit to Jesse Mohrland of Microsoft and Microsoft Vulnerability Research (MSVR).
- [76034] Low CVE-2011-1811: Browser crash with lots of form submissions. Credit to “DimitrisV22”.
- [$1337] [77026] Medium CVE-2011-1812: Extensions permission bypass. Credit to kuzzcc.
- [78516] High CVE-2011-1813: Stale pointer in extension framework. Credit to Google Chrome Security Team (Inferno).
- [79362] Medium CVE-2011-1814: Read from uninitialized pointer. Credit to Eric Roman of the Chromium development community.
- [79862] Low CVE-2011-1815: Extension script injection into new tab page. Credit to kuzzcc.
- [80358] Medium CVE-2011-1816: Use-after-free in developer tools. Credit to kuzzcc.
- [$500] [81916] Medium CVE-2011-1817: Browser memory corruption in history deletion. Credit to Collin Payne.
- [$1000] [81949] High CVE-2011-1818: Use-after-free in image loader. Credit to miaubiz.
- [$1000] [83010] Medium CVE-2011-1819: Extension injection into chrome:// pages. Credit to Vladislavas Jarmalis, plus subsequent independent discovery by Sergey Glazunov.
- [$3133.7] [83275] High CVE-2011-2332: Same origin bypass in v8. Credit to Sergey Glazunov.
- [$1000] [83743] High CVE-2011-2342: Same origin bypass in DOM. Credit to Sergey Glazunov.
In addition, we would like to thank David Levin of the Chromium development community, miaubiz, Christian Holler and Martin Barbella for working with us in the development cycle and preventing bugs from ever reaching the stable channel. Various rewards were issued.
We’d also like to call particular attention to Sergey Glazunov’s $3133.7 reward. Although the linked bug is not of critical severity, it was accompanied by a beautiful chain of lesser severity bugs which demonstrated critical impact. It deserves a more detailed write-up at a later date.
You can find out more about Chrome 12 at the official Chrome Blog. The full list of changes is available in the SVN revision logs (Trunk, Branch). Interested in switching to the Stable channel? Find out how. If you find a new issue, please let us know by filing a bug.
Stable Channel Update
The Chrome Stable channel has been updated to 11.0.696.77 for all platforms. This release contains an updated version of Adobe Flash. Interested in switching to the Stable channel? Find out how.
Stable Channel Update - The Stable channel has been updated to 11.0.696.71 for the Macintosh, Windows, Linux and Chrome Frame platforms
The Stable channel has been updated to 11.0.696.71 for the Macintosh, Windows, Linux and Chrome Frame platforms
Security fixes and rewards:
- [72189] Low CVE-2011-1801: Pop-up blocker bypass. Credit to Chamal De Silva.
- [$1000] [82546] High CVE-2011-1804: Stale pointer in floats rendering. Credit to Martin Barbella.
- [82873] Critical CVE-2011-1806: Memory corruption in GPU command buffer. Credit to Google Chrome Security Team (Cris Neckar).
- [82903] Critical CVE-2011-1807: Out-of-bounds write in blob handling. Credit to Google Chrome Security Team (Inferno) and Kostya Serebryany of the Chromium development community.
- REGRESSION: selection extended by arrow keys flickers on LinkedIn.com. (Issue 83197).
- Have ConnectBackupJob try IPv4 first to hide potential long IPv6 connect timeout (Issue 81686).
- Mac plugin crashes are too low in stats (Issue 82172).
- Incorrect ACLs on the archived copy of setup.exe (Issue 82424)
Stable Channel Update
Please see the Chromium security page for more detail. Note that the referenced bugs may be kept private until a majority of our users are up to date with the fix.
- [64046] High CVE-2011-1799: Bad casts in Chromium WebKit glue. Credit to Google Chrome Security Team (SkyLined).
- [80608] High CVE-2011-1800: Integer overflows in SVG filters. Credit to Google Chrome Security Team (Cris Neckar).
Beta and Stable Channel Update - The Beta and Stable channels have been updated to 11.0.696.65
The following bugs were fixed:
- After deleting bookmarks on the Bookmark managers, the bookmark bar doesn't display properly with existing bookmarks. (Issue 80580).
- About Google Chrome window shows unknown channel for 11.0.696.57 (Issue 80683).
- Chrome/Mac seems to clobber focus when uploading attachments to Gmail with the flash-based uploader (Issue 77172).
- Also included is an updated version of Flash Player 10.2.
Beta and Stable Channel Update
- REGRESSION: Windows painting issue while switching Chrome 11 window with overlapped app. (Issue 74604).
Chrome Stable Update
The Google Chrome team is happy to announce the arrival of Chrome 11.0.696.57 to the Stable Channel for Windows, Mac, Linux, and Chrome Frame. Chrome 11 contains some really great improvements including speech input through HTML.
We’re pleased to associate a record $16,500 of rewards with this patch.
- [61502] High CVE-2011-1303: Stale pointer in floating object handling. Credit to Scott Hess of the Chromium development community and Martin Barbella.
- [70538] Low CVE-2011-1304: Pop-up block bypass via plug-ins. Credit to Chamal De Silva.
- [Linux / Mac only] [70589] Medium CVE-2011-1305: Linked-list race in database handling. Credit to Kostya Serebryany of the Chromium development community.
- [$500] [71586] Medium CVE-2011-1434: Lack of thread safety in MIME handling. Credit to Aki Helin.
- [72523] Medium CVE-2011-1435: Bad extension with ‘tabs’ permission can capture local files. Credit to Cole Snodgrass.
- [Linux only] [72910] Low CVE-2011-1436: Possible browser crash due to bad interaction with X. Credit to miaubiz.
- [$1000] [73526] High CVE-2011-1437: Integer overflows in float rendering. Credit to miaubiz.
- [$1000] [74653] High CVE-2011-1438: Same origin policy violation with blobs. Credit to kuzzcc.
- [Linux only] [74763] High CVE-2011-1439: Prevent interference between renderer processes. Credit to Julien Tinnes of the Google Security Team.
- [$1000] [75186] High CVE-2011-1440: Use-after-free with tag and CSS. Credit to Jose A. Vazquez.
- [$500] [75347] High CVE-2011-1441: Bad cast with floating select lists. Credit to Michael Griffiths.
- [$1000] [75801] High CVE-2011-1442: Corrupt node trees with mutation events. Credit to Sergey Glazunov and wushi of team 509.
- [$1000] [76001] High CVE-2011-1443: Stale pointers in layering code. Credit to Martin Barbella.
- [$500] [Linux only] [76542] High CVE-2011-1444: Race condition in sandbox launcher. Credit to Dan Rosenberg.
- [76646] Medium CVE-2011-1445: Out-of-bounds read in SVG. Credit to wushi of team509.
- [$3000] [76666] [77507] [78031] High CVE-2011-1446: Possible URL bar spoofs with navigation errors and interrupted loads. Credit to kuzzcc.
- [$1000] [76966] High CVE-2011-1447: Stale pointer in drop-down list handling. Credit to miaubiz.
- [$1000] [77130] High CVE-2011-1448: Stale pointer in height calculations. Credit to wushi of team509.
- [$1000] [77346] High CVE-2011-1449: Use-after-free in WebSockets. Credit to Marek Majkowski.
- [77349] Low CVE-2011-1450: Dangling pointers in file dialogs. Credit to kuzzcc.
- [$2000] [77463] High CVE-2011-1451: Dangling pointers in DOM id map. Credit to Sergey Glazunov.
- [$500] [77786] Medium CVE-2011-1452: URL bar spoof with redirect and manual reload. Credit to Jordi Chancel.
- [$1500] [79199] High CVE-2011-1454: Use-after-free in DOM id handling. Credit to Sergey Glazunov.
- [79361] Medium CVE-2011-1455: Out-of-bounds read with multipart-encoded PDF. Credit to Eric Roman of the Chromium development community.
- [79364] High CVE-2011-1456: Stale pointers with PDF forms. Credit to Eric Roman of the Chromium development community.
We would also like to thank miaubiz, kuzzcc, Sławomir Błażek, Drew Yao and Braden Thomas of Apple Product Security and Christian Hollier for working with us during the development cycle and helping prevent bugs from ever reaching the stable channel.
Stable Channel Update
Please see the Chromium security page for more detail. Note that the referenced bugs may be kept private until a majority of our users are up to date with the fix.
- [$500] [Windows only] [70070] Critical CVE-2011-1300: Off-by-three in GPU process. Credit to yuri.ko616.
- [75629] Critical CVE-2011-1301: Use-after-free in the GPU process. Credit to Google Chrome Security Team (Inferno).
- [$1000] [78524] Critical CVE-2011-1302: Heap overflow in the GPU process. Credit to Christoph Diehl.
Stable Channel Update
Please see the Chromium security page for more detail. Note that the referenced bugs may be kept private until a majority of our users are up to date with the fix.
Stable and Beta Channel Updates

