Vulnerabilities / Threats
5/16/2012
11:34 AM
Connect Directly
RSS
E-Mail
50%
50%
Repost This

Google Chrome 19 Debuts, With 20 Bug Patches

Latest release of browser also adds the ability to synchronize open tabs across devices.

Google Drive: 10 Alternatives To See
Google Drive: 10 Alternatives To See
(click image for larger view and for slideshow)
Google Tuesday released version 19 of its Chrome browser, which includes fixes for 20 vulnerabilities, as well as a new feature for sharing open tabs across different devices. But Google said the feature won't be widely available for another few weeks.

The new version of Chrome is available for Windows, Mac, Linux, and Chrome Frame. All current Chrome installations should auto-update to the latest version over the next few days.

Google releases a new, stable version of Chrome about every six to eight weeks.

With the release of Chrome 19, Google also distributed $7,500 as part of its bug bounty program. None of the patched bugs were "critical," meaning--per the Common Vulnerability Scoring System (CVSS)--that attackers could have potentially used them to remotely execute arbitrary code. However, eight of the vulnerabilities patched in the new version of Chrome are of "high" severity, seven are ranked as "medium," and five are of "low" severity.

[ Read It's Browser Version Madness! ]

Six of the bugs were spotted by Google or the broader Chromium (Google Chrome OS) community. A low-risk, Windows-only "bad search path for Windows Media Player plug-in" bug was credited to Microsoft and Microsoft Vulnerability Research.

Full information about all of the bugs has yet to be released; Google typically waits to release detailed information until the majority of Chrome users have received related patches. But many of the patched bugs relate to memory errors in C/C++. Not coincidentally, Google said that a homegrown tool, AddressSanitizer, had been used by researchers to detect many of the patched vulnerabilities.

Unusually, Google also distributed an additional $9,000 in rewards to Aki Helin at the Oulu University Secure Programming Group in Finland, as well as Sławomir Błażek, Chamal de Silva, miaubiz, Arthur Gerkis, and Christian Holler "for working with us during the development cycle and preventing security regressions from ever reaching the stable channel." All feature prominently in Google's Security Hall of Fame, which lists researchers who have helped "make Chromium safer."

Google software engineer and "tab-wrangling server jockey" Raz Mathias explained how Chrome's new tab synchronization feature will work. "When you're signed in to Chrome, your open tabs are synced across all your devices, so you can quickly access them from the 'Other devices' menu on the New Tab page," he said in a blog post. "If you've got Chrome for Android Beta, you can open the same recipe tab right on your phone when you run out to the store for more ingredients. The back and forward buttons will even work, so you can pick up browsing right where you left off."

Chrome isn't the only browser now offering tab synchronization. Notably, Mozilla added tab synchronization to Firefox 4, which it released in 2010.

At this interactive Enterprise Mobility Virtual Event, experts and solution providers will offer detailed insight into how to bring some order to the mobile industry innovation chaos. When you register, you will gain access to live webcast presentations and virtual booths packed with free resources. It happens May 17.

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2012-3946
Published: 2014-04-24
Cisco IOS before 15.3(2)S allows remote attackers to bypass interface ACL restrictions in opportunistic circumstances by sending IPv6 packets in an unspecified scenario in which expected packet drops do not occur for "a small percentage" of the packets, aka Bug ID CSCty73682.

CVE-2012-5723
Published: 2014-04-24
Cisco ASR 1000 devices with software before 3.8S, when BDI routing is enabled, allow remote attackers to cause a denial of service (device reload) via crafted (1) broadcast or (2) multicast ICMP packets with fragmentation, aka Bug ID CSCub55948.

CVE-2013-6738
Published: 2014-04-24
Cross-site scripting (XSS) vulnerability in IBM SmartCloud Analytics Log Analysis 1.1 and 1.2 before 1.2.0.0-CSI-SCALA-IF0003 allows remote attackers to inject arbitrary web script or HTML via an invalid query parameter in a response from an OAuth authorization endpoint.

CVE-2014-0188
Published: 2014-04-24
The openshift-origin-broker in Red Hat OpenShift Enterprise 2.0.5, 1.2.7, and earlier does not properly handle authentication requests from the remote-user auth plugin, which allows remote attackers to bypass authentication and impersonate arbitrary users via the X-Remote-User header in a request to...

CVE-2014-2391
Published: 2014-04-24
The password recovery service in Open-Xchange AppSuite before 7.2.2-rev20, 7.4.1 before 7.4.1-rev11, and 7.4.2 before 7.4.2-rev13 makes an improper decision about the sensitivity of a string representing a previously used but currently invalid password, which allows remote attackers to obtain potent...

Best of the Web