Subscribe to AfterDawn's weekly newsletter.
Version history for Google Chrome
<<Back to software description
Changes for v16.0.912.77 - v17.0.963.46
- New Extensions APIs
- Updated Omnibox Prerendering
- Download Scanning Protection
- Many other small changes
Changes for v16.0.912.75 - v16.0.912.77
- Bug fixes
Changes for v16.0.912.63 - v16.0.912.75
- [$1000] [106672] High CVE-2011-3921: Use-after-free in animation frames. Credit to Boris Zbarsky of Mozilla
- [$1000] [107128] High CVE-2011-3919: Heap-buffer-overflow in libxml. Credit to Jüri Aedla
- [108006] High CVE-2011-3922: Stack-buffer-overflow in glyph handling. Credit to Google Chrome Security Team (Cris Neckar)
Changes for v15.0.874.121 - v16.0.912.63
- Chrome 16 contains some really great improvements including enhancements to Sync and the ability to create multiple profiles on a single instance of Chrome.
Changes for v15.0.874.120 - v15.0.874.121
- ?Updated V8 - 3.5.10.24
- ?This build contains the fix to a regression: SVG in iframe doesn't use specified dimensions
Changes for v15.0.874.106 - v15.0.874.120
- ?Updated V8 - 3.5.10.23
- ?Fix small print sizing issues
- ?This new build also contains a new version of Flash which contains security fixes. (Release Notes)
Changes for v15.0.874.102 - v15.0.874.106
- The Stable channel has been updated to 15.0.874.106 for Windows, Mac, Linux, and Chrome Frame. This release fixes login issues to Barrons Online and The Wall Street Journal.
Changes for v14.0.835.202 - v15.0.874.102
- Chrome 15 contains some really great improvements including a new New Tab page.
Changes for v14.0.835.187 - v14.0.835.202
- Security fixes and rewards:
- Please see the Chromium security page for more detail. Note that the referenced bugs may be kept private until a majority of our users are up to date with the fix.
- High CVE-2011-2876: Use-after-free in text line box handling. Credit to miaubiz.
- High CVE-2011-2877: Stale font in SVG text handling. Credit to miaubiz.
- High CVE-2011-2878: Inappropriate cross-origin access to the window prototype. Credit to Sergey Glazunov.
- High CVE-2011-2879: Lifetime and threading issues in audio node handling. Credit to Google Chrome Security Team (Inferno).
- High CVE-2011-2880: Use-after-free in the v8 bindings. Credit to Sergey Glazunov.
- High CVE-2011-2881: Memory corruption with v8 hidden objects. Credit to Sergey Glazunov.
- Critical CVE-2011-3873: Memory corruption in shader translator. Credit to Zhenyao Mo of the Chromium development community.
Changes for v14.0.835.186 - v14.0.835.187
- These updates should help repair Chrome installs that were broken due to the issue with Microsoft Security Essentials
Changes for v14.0.835.163 - v14.0.835.186
- Pepper flash: update to 10.3.200.107
- Crash fixes
Changes for v13.0.782.218 - v13.0.782.220
- We're revoking trust for SSL certificates issued by DigiNotar-controlled intermediate CAs used by the Dutch PKIoverheid program.
Changes for v12.0.742.112 - v13.0.782.112
- includes an updated version of Flash Player
Changes for v12.0.742.91 - v12.0.742.100
- This release contains an updated version of Adobe Flash
Changes for v11.0.696.77 - v12.0.742.91
- Hardware accelerated 3D CSS
- New Safe Browsing protection against downloading malicious files
- Ability to delete Flash cookies from inside Chrome
- Launch Apps by name from the Omnibox
- Integrated Sync into new settings pages
- Improved screen reader support
- New warning when hitting Command-Q on Mac
- Removal of Google Gears
Changes for v11.0.696.71 - v11.0.696.77
- This release contains an updated version of Adobe Flash.
Changes for v11.0.696.68 - v11.0.696.71
- [72189] Low CVE-2011-1801: Pop-up blocker bypass. Credit to Chamal De Silva.
- [$1000] [82546] High CVE-2011-1804: Stale pointer in floats rendering. Credit to Martin Barbella.
- [82873] Critical CVE-2011-1806: Memory corruption in GPU command buffer. Credit to Google Chrome Security Team (Cris Neckar).
- [82903] Critical CVE-2011-1807: Out-of-bounds write in blob handling. Credit to Google Chrome Security Team (Inferno) and Kostya Serebryany of the Chromium development community.
Changes for v11.0.696.60 - v11.0.696.65
- After deleting bookmarks on the Bookmark managers, the bookmark bar doesn't display properly with existing bookmarks. (Issue 80580).
- About Google Chrome window shows unknown channel for 11.0.696.57 (Issue 80683).
- Chrome/Mac seems to clobber focus when uploading attachments to Gmail with the flash-based uploader (Issue 77172).
- Also included is an updated version of Flash Player 10.2.
Changes for v10.0.648.205 - v11.0.696.57
- [61502] High CVE-2011-1303: Stale pointer in floating object handling. Credit to Scott Hess of the Chromium development community and Martin Barbella.
- [70538] Low CVE-2011-1304: Pop-up block bypass via plug-ins. Credit to Chamal De Silva.
- [Linux / Mac only] [70589] Medium CVE-2011-1305: Linked-list race in database handling. Credit to Kostya Serebryany of the Chromium development community.
- [$500] [71586] Medium CVE-2011-1434: Lack of thread safety in MIME handling. Credit to Aki Helin.
- [72523] Medium CVE-2011-1435: Bad extension with ‘tabs’ permission can capture local files. Credit to Cole Snodgrass.
- [Linux only] [72910] Low CVE-2011-1436: Possible browser crash due to bad interaction with X. Credit to miaubiz.
- [$1000] [73526] High CVE-2011-1437: Integer overflows in float rendering. Credit to miaubiz.
- [$1000] [74653] High CVE-2011-1438: Same origin policy violation with blobs. Credit to kuzzcc.
- [Linux only] [74763] High CVE-2011-1439: Prevent interference between renderer processes. Credit to Julien Tinnes of the Google Security Team.
- [$1000] [75186] High CVE-2011-1440: Use-after-free with tag and CSS. Credit to Jose A. Vazquez.
- [$500] [75347] High CVE-2011-1441: Bad cast with floating select lists. Credit to Michael Griffiths.
- [$1000] [75801] High CVE-2011-1442: Corrupt node trees with mutation events. Credit to Sergey Glazunov and wushi of team 509.
- [$1000] [76001] High CVE-2011-1443: Stale pointers in layering code. Credit to Martin Barbella.
- [$500] [Linux only] [76542] High CVE-2011-1444: Race condition in sandbox launcher. Credit to Dan Rosenberg.
- [76646] Medium CVE-2011-1445: Out-of-bounds read in SVG. Credit to wushi of team509.
- [$3000] [76666] [77507] [78031] High CVE-2011-1446: Possible URL bar spoofs with navigation errors and interrupted loads. Credit to kuzzcc.
- [$1000] [76966] High CVE-2011-1447: Stale pointer in drop-down list handling. Credit to miaubiz.
- [$1000] [77130] High CVE-2011-1448: Stale pointer in height calculations. Credit to wushi of team509.
- [$1000] [77346] High CVE-2011-1449: Use-after-free in WebSockets. Credit to Marek Majkowski.
- [77349] Low CVE-2011-1450: Dangling pointers in file dialogs. Credit to kuzzcc.
- [$2000] [77463] High CVE-2011-1451: Dangling pointers in DOM id map. Credit to Sergey Glazunov.
- [$500] [77786] Medium CVE-2011-1452: URL bar spoof with redirect and manual reload. Credit to Jordi Chancel.
- [$1500] [79199] High CVE-2011-1454: Use-after-free in DOM id handling. Credit to Sergey Glazunov.
- [79361] Medium CVE-2011-1455: Out-of-bounds read with multipart-encoded PDF. Credit to Eric Roman of the Chromium development community.
- [79364] High CVE-2011-1456: Stale pointers with PDF forms. Credit to Eric Roman of the Chromium development community.
Changes for v10.0.648.127 - v10.0.648.133
- Security fixes and rewards:
- Please see the Chromium security page for more detail. Note that the referenced bugs may be kept private until a majority of our users are up to date with the fix.
- [$1337] CVE-2011-1290 [75712] High Memory corruption in style handling. Credit to Vincenzo Iozzo, Ralf Philipp Weinmann and Willem Pinckaers reported through ZDI.
Changes for v7.0.517.44 - v8.0.552.215
- [17655] Low Possible pop-up blocker bypass. Credit to Google Chrome Security Team (SkyLined).
- [55745] Medium Cross-origin video theft with canvas. Credit to Nirankush Panchbhai and Microsoft Vulnerability Research (MSVR).
- [56237] Low Browser crash with HTML5 databases. Credit to Google Chrome Security Team (Inferno).
- [58319] Low Prevent excessive file dialogs, possibly leading to browser crash. Credit to Cezary Tomczak (gosu.pl).
- [$500] [59554] High Use after free in history handling. Credit to Stefan Troger.
- [Linux / Mac] [59817] Medium Make sure the “dangerous file types” list is uptodate with the Windows platforms. Credit to Billy Rios of the Google Security Team.
- [61701] Low Browser crash with HTTP proxy authentication. Credit to Mohammed Bouhlel.
- [61653] Medium Out-of-bounds read regression in WebM video support. Credit to Google Chrome Security Team (Chris Evans), based on earlier testcases from Mozilla and Microsoft (MSVR).
- [$1000] [62127] High Crash due to bad indexing with malformed video. Credit to miaubiz.
- [62168] Medium Possible browser memory corruption via malicious privileged extension. Credit to kuzzcc.
- [$1000] [62401] High Use after free with SVG animations. Credit to Slawomir Blazek.
- [$500] [63051] Medium Use after free in mouse dragging event handling. Credit to kuzzcc.
- [$1000] [63444] High Double free in XPath handling. Credit to Yang Dingning from NCNIPC, Graduate University of Chinese Academy of Sciences.
Changes for v5.0.371.0 Beta - v5.0.375.29 Beta
- Geolocation
- File drag-and-drop in Gmail
- App Cache
- Web sockets
Changes for v3.0.187.1 Beta - v3.0.189.0
- [r18038] [CRASH] Fix crash when opening and closing TaskManager multiple times. (Issue: 13361)
- [r18052] When closing a tab with the close box, highlight the close box of the new tab that slides into place. (Issue: 8838)
- [r18061] [MAC] Clicking a file link in the download manager should open the file. (Issue: 13552)
- [r18085] [LINUX] Ctrl-Q should quit.
- [r18086] [CRASH] Attempt to fix crash suspected to occur when closing the browser during certain page transitions. (Issue: 11493)
- [r18087] [LINUX] [CRASH] Fix browser crash if the renderer dies quickly. (Issue: 13715)
- [r18099] Don't auto-spell-correct abbreviations, e.g. "WTO" should not get corrected to "TWO". (Issue: 12921)
- [r18102] Show the time remaining in the downloads page. (Issue: 13386)
- [r18113, r18207, r18285] [LINUX] Add UI for blocked popups. (Issue: 12843)
- [r18116] Temporarily disable extensions in incognito mode. (Issue: 12326)
- [r18121] Show a scrollbar instead of truncating long lists (e.g. the list of languages in the Options UI). (Issue: 13438)
- [r18151, r18458, r18532] [CRASH] Fix crash when closing Incognito window after downloading a file from it. (Issue: 13681)
- [r18157] [CRASH] Fix rare renderer crash having to do with caching and V8 garbage collection. (Issue: 13780)
- [r18170] Show context menu for browser frame on mouseup, not mousedown. (Issue: 5695)
- [r18173] [MAC] Processes should not appear to be "Not Responding" in Activity Monitor. (Issue: 11319)
- [r18174] [LINUX] Resize tabs on a timer after the mouse leaves the tabstrip (like Windows). (Issue: 13471)
- [r18176] [LINUX] Pressing arrow keys inside the Find bar should scroll the page. (Issue: 12697)
- [r18196] [LINUX] Shift-enter in find bar should search backwards. (Issue: 13520)
- [r18217] Fix controls being cut off on the right side of the Fonts & Languages dialog. (Issue: 13366)
- [r18225] [LINUX] Context-menu options like copy/paste and correct misspelling were not working on some sites. (Issues: 13404, 13554)
- [r18290] [WINDOWS] Show accurate network usage for browser process in Chrome's Task Manager. (Issue: 13958)
- [r18292] Fix RTL issues on download bar. (Issues: 6103, 13217)
- [r18316] Implement signature verification for all extensions. (Issue: 12114)
- [r18335, r18402] Fix several problems when doing reverse-focus-traversal (using shift-tab). (Issue: 6785, 6871)
- [r18338] [CRASH] Fix crash when visiting site with invalid SSL cert. (Issue: 13979)
- [r18340] [MAC] Add bookmark bar favicons. (Issue: 8381)
- [r18344, r18463] [LINUX] [CRASH] Fix crashes and other problems (especially with dragging) in bookmark manager and bookmark bar. (Issue: 13110, 14019)
- [r18352] Make extension processes visible in the Chrome Task Manager. (Issue: 12127)
- [r18389] [MAC] Fix favicons getting corrupted on New Tab Page (only fixes new favicons, not existing corrupt ones).
- [r18390, r18491] [MAC] Incognito windows should have an Incognito graphic. (Issue: 12536)
- [r18401] Fix tab dragging glitches in RTL UIs. (Issue: 6223)
- [r18408, r18490, r18505] [MAC] Improve tooltip support. (Issue: 13995)
- [r18465] Support XHR in HTML5 Web Workers. (Issue: 4361)
- [r18472] [MAC] Don't hide the window when clicking sites in the New Tab Page. (Issue: 14144)
- [r18479] Remove advanced option controls relating to mixed content.
- [r18497] [LINUX] Fix memory leak.
- [r18503] [MAC] Beginnings of

