Application Security
1/25/2010
07:14 PM
Connect Directly
Google+
LinkedIn
Twitter
RSS
E-Mail
50%
50%

Google Chrome Gets Extensions, APIs

With support for user-installed extensions, Google Chrome presents stronger competition to the more established Web browsers.

Only days after Mozilla introduced Firefox 3.6, Google has rolled out a new stable release of Google Chrome for Windows.

Google maintains three separate tracks for its Chrome Web browser: developer, beta, and stable.

The updated stable release bring support for Chrome Extensions, a feature that users of Chrome's developer and beta releases have had since late last year. Extensibility has been one of the major factors in the success of Firefox.

And as with Firefox, some of the most popular extensions for Chrome block ads.

"Google Chrome extensions use the same multiprocess technology that makes the browser fast and more secure, so that extensions won't crash or slow down your browser," said Google product manager Ian Fette in a blog post.

Google has enabled extensions in the Google Chrome for Linux beta and it plans to do the same shortly for Chrome on the Mac.

The updated version of Chrome for Windows also adds support for several new HTML and JavaScript APIs. These include the Web SQL Database API, which allows local storage of structured data; the local storage portion of the Web Storage API, a simpler local storage mechanism; WebSockets, a way to send data back and forth over a persistent communication channel; and a Windows-only notification API, for passing non-disruptive updates to a panel in the user's status-bar area.

In a separate blog post, Fette also said that Google is working to implement a service called Application Cache, which allows the serving of HTML and JavaScript that references Web SQL data. Its engineers are also working on the SessionStorage part of the Web Storage API.

While Firefox use continues to grow, Google's ongoing efforts to polish Chrome appear to be prompting some Firefox fans to reconsider their browser choice. A thread on Reddit about Chrome use suggests that Google's focus on browser basics like speed, stability, and security resonates with users.

Running Mozilla's Dromaeo JavaScript test on Windows XP, Chrome 4.0.302.3 beat Firefox 3.6 in three out of four of the speed trials, with a final score of 139.19 to 83.90.

At the end of this year, Google plans to release Chrome OS, an operating system based on its Web browser.

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Dark Reading, January 2015
To find and fix exploits aimed directly at your business, stop waiting for alerts and become a proactive hunter.
Flash Poll
DevOps’ Impact on Application Security
DevOps’ Impact on Application Security
Managing the interdependency between software and infrastructure is a thorny challenge. Often, it’s a “developers are from Mars, systems engineers are from Venus” situation.
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2013-7402
Published: 2014-12-17
Multiple unspecified vulnerabilities in request.c in c-icap 0.2.x allow remote attackers to cause a denial of service (crash) via a crafted ICAP request.

CVE-2014-5437
Published: 2014-12-17
Multiple cross-site request forgery (CSRF) vulnerabilities in ARRIS Touchstone TG862G/CT Telephony Gateway with firmware 7.6.59S.CT and earlier allow remote attackers to hijack the authentication of administrators for requests that (1) enable remote management via a request to remote_management.php,...

CVE-2014-5438
Published: 2014-12-17
Cross-site scripting (XSS) vulnerability in ARRIS Touchstone TG862G/CT Telephony Gateway with firmware 7.6.59S.CT and earlier allows remote authenticated users to inject arbitrary web script or HTML via the computer_name parameter to connected_devices_computers_edit.php.

CVE-2014-7170
Published: 2014-12-17
Race condition in Puppet Server 0.2.0 allows local users to obtain sensitive information by accessing it in between package installation or upgrade and the start of the service.

CVE-2014-7285
Published: 2014-12-17
The management console on the Symantec Web Gateway (SWG) appliance before 5.2.2 allows remote authenticated users to execute arbitrary OS commands by injecting command strings into unspecified PHP scripts.

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
Join us Wednesday, Dec. 17 at 1 p.m. Eastern Time to hear what employers are really looking for in a chief information security officer -- it may not be what you think.