Tuesday, July 31, 2012

Stable Channel Release


The Chrome team is excited to announce the release of Chrome 21 to the Stable Channel. 21.0.1180.57 for Mac and Linux. 21.0.1180.60 for Windows and Chrome Frame. Chrome 21 contains a number of new features including a new API for high-quality video and audio communication. More detailed updates are available on the Chrome Blog.  


Security fixes and rewards:
Please see the Chromium security page for more detail. Note that the referenced bugs may be kept private until a majority of our users are up to date with the fix.

  • [Linux only] [125225] Medium CVE-2012-2846: Cross-process interference in renderers. Credit to Google Chrome Security Team (Julien Tinnes).
  • [127522] Low CVE-2012-2847: Missing re-prompt to user upon excessive downloads. Credit to Matt Austin of Aspect Security.
  • [127525] Medium CVE-2012-2848: Overly broad file access granted after drag+drop. Credit to Matt Austin of Aspect Security.
  • [128163] Low CVE-2012-2849: Off-by-one read in GIF decoder. Credit to Atte Kettunen of OUSPG.
  • [130251] [130592] [130611] [131068] [131237] [131252] [131621] [131690] [132860] Medium CVE-2012-2850: Various lower severity issues in the PDF viewer. Credit to Mateusz Jurczyk of Google Security Team, with contributions by Gynvael Coldwind of Google Security Team.
  • [132585] [132694] [132861] High CVE-2012-2851: Integer overflows in PDF viewer. Credit to Mateusz Jurczyk of Google Security Team, with contributions by Gynvael Coldwind of Google Security Team.
  • [134028] High CVE-2012-2852: Use-after-free with bad object linkage in PDF. Credit to Alexey Samsonov of Google.
  • [134101] Medium CVE-2012-2853: webRequest can interfere with the Chrome Web Store. Credit to Trev of Adblock.
  • [134519] Low CVE-2012-2854: Leak of pointer values to WebUI renderers. Credit to Nasko Oskov of the Chromium development community.
  • [134888] High CVE-2012-2855: Use-after-free in PDF viewer. Credit to Mateusz Jurczyk of Google Security Team, with contributions by Gynvael Coldwind of Google Security Team.
  • [134954] [135264] High CVE-2012-2856: Out-of-bounds writes in PDF viewer. Credit to Mateusz Jurczyk of Google Security Team, with contributions by Gynvael Coldwind of Google Security Team.
  • [$1000] [136235] High CVE-2012-2857: Use-after-free in CSS DOM. Credit to Arthur Gerkis.
  • [$1000] [136894] High CVE-2012-2858: Buffer overflow in WebP decoder. Credit to Jüri Aedla.
  • [Linux only] [137541] Critical CVE-2012-2859: Crash in tab handling. Credit to Jeff Roberts of Google Security Team.
  • [137671] Medium CVE-2012-2860: Out-of-bounds access when clicking in date picker. Credit to Chamal de Silva.

Many of the above bugs were detected using AddressSanitizer.

We’d also like to thank Drew Yao / Braden Thomas / Jim Smith (all Apple Product Security), Kostya Serebryany of the Chromium development community, Atte Kettunen of OUSPG and Bernhard Bauer of the Chromium development community for working with us during the development cycle and preventing security regressions from ever reaching the stable channel.




Full details about what changes are in this release are available in the SVN revision log.  Interested in hopping on the stable channel?  Find out how.  If you find a new issue, please let us know by filing a bug.

Karen Grunberg
Google Chrome


Stable Channel Update for Chrome OS


The Stable channel has been updated to 20.0.1132.59 (Platform version: 2268.124.0) for Chrome OS (Chromebooks Acer AC700, Samsung Series 5, Samsung Chromebook Series 5 550 and Cr-48, and Samsung Chromebox Series 3).

This build contains a number of stability improvements.

Some highlights of these changes are:

  • Fixed 133988: Network dropdown in the first screen when setting up the network may not show the entire list of networks.
  • Fixed 31651: Disabling 3G mobile data on the system would cause it to become permanently disabled.
  • Fixed issue with Enterprise customers being unable to enroll due to a timezone mismatch issue.


If you find new issues, please let us know by visiting our help site or filing a bug. Interested in switching channels? Find out how. You can submit feedback using ‘Report an issue’ under the wrench menu.


Danielle Drew
Google Chrome

Beta Channel Update


The Beta channel has been updated to 21.0.1180.60 for Windows and Chrome Frame


This build should fix most of the choppy and distorted audio issues  (Issue: 136624). If you've seen these issues with the Beta, please leave us an update on the bug.


If you find new issues, please let us know by filing a bug at http://code.google.com/p/chromium/issues/entry

Karen Grunberg
Google Chrome

Monday, July 30, 2012

Dev Channel Update

The Dev channel has been updated to 22.0.1221.0 for Windows and Mac (Update: also 22.0.1221.1 for Linux).  This update has an updated version of V8 (3.12.16.0) along with other improvements.  A complete log of what changed can be found in the svn revision log.  Instructions and download links for our different release channels are available on the Chromium wiki.  If you find what you think is a new bug, please file it in our issue tracker.

Jason Kersey
Google Chrome

Thursday, July 26, 2012

Beta Channel Update

The Beta channel has been updated to 21.0.1180.57 for Windows, Mac, Linux and ChromeFrame platforms

All
  • Fixed Youtube Drag & Drop Upload Not Working (Issue: 137024)
Mac
  • Fixed Calendar picker for <input type=date> is garbled in HiDPI (Issue: 136958)
    More details about additional changes are available in the svn log of all revisions. 

    If you find new issues, please let us know by filing a bug at http://code.google.com/p/chromium/issues/entry

    Karen Grunberg
    Google Chrome

    Beta Channel Update for Chrome OS


    The Beta channel has been updated to 21.0.1180.55 (Platform versions: 2465.97.0) for Chromebooks (Acer AC700, Samsung Series 5 550, Samsung Chromebook Series 3, and Cr-48) and Samsung Chromebox Series 3. This build contains a number of UI, stability & security improvements. 

    Highlights of these changes are:
    • Update Netflix plugin to 2.0.5 
    • Wifi stability fixes
    • 3G stability fixes
    • Audio fixes
    • UI fixes

    Known Issues:

    • 32327 - System suspend while streaming audio 
    • 137273  - Connecting to hidden networks fails when you try to connect to it for the first time
    • 31866 -  Unable to enable mobile data for locked SIM on y3300 and y3400 modems
    • 136864  - Multiple options Disabled in the Certificate Manager.

    If you find new issues, please let us know by visiting our help site or filing a bug. Interested in switching channels? Find out how. You can submit feedback using ‘Report an issue’ under the wrench menu.

    Josafat Garcia

    Google Chrome

    Wednesday, July 25, 2012

    Beta Channel Update


    The Beta channel has been updated to 21.0.1180.55 for Windows, Mac, Linux and ChromeFrame platforms

    All
    • Several crash fixes (Issues: 131310134574)
    • Can't press Enter to save to PDF (Issue: 137690)
    Windows
    • Several Pepper Flash Fixes (Issues: 134615)
    • This build should also fix audio issues with flash, please let us know if you still experience audio problems
    Mac
    • Chrome returns black screen with no logged errors on WebGL examples (Issue: 138088)
    • Chrome Extension dropdown menus corrupted for when compositing is enabled (Issue: 135382)
    • Fixed Websites do not render completely in Presentation Mode (Issue: 137336)
      More details about additional changes are available in the svn log of all revisions. 

      If you find new issues, please let us know by filing a bug at http://code.google.com/p/chromium/issues/entry

      Karen Grunberg
      Google Chrome

      Dev Channel Update for Chrome OS

      The Dev channel has been updated to 22.0.1215.0 (Platform versions: 2650.0.0) for Chromebooks (Acer AC700, Samsung Series 5, and Cr-48). This release contains functional and stability improvements.


      Highlights of these changes are:
      • UI improvements on start and lock screens
      Known issues:
      • 32909 - Purchasing additional data for a Verizon 3G account is currently not functioning. Workaround: Contact Verizon to purchase additional data.
      • 32766 - Cr-48 machines will go through the out of box sign-up experience after this update, however all data and settings on the machine will be preserved.
      • 32906 - Cr-48 machines fail to save new users where the new user is created and the system is not restarted prior to the next autoupdate. Workaround: After creating a new user, reboot the system and check that the user still exists.
      • 32922Connected hidden network is unavailable immediately after resume. Workaround: Wait several seconds for the network to become available.
      • 32923OpenVPN with no-OTP does not allow login with a correct username/password.
      • 138967 - Photo editor will not complete edit actions.
      If you find new issues, please let us know by visiting our help site or filing a bug. Interested in switching channels? Find out how. You can submit feedback using ‘Report an issue’ under the wrench menu.

      Danielle Drew

      Google Chrome

      Monday, July 23, 2012

      Dev Channel Update

      [Note: The Windows push has been halted, we've encountered an error w/ our installer that's prevent an update w/ Error 22. We are tracking the issue w/ bug 138658 and hope to update everyone soon.]


      The Dev channel has been updated to 22.0.1215.0 for Windows, Mac, Linux and Chrome Frame.  This build has an update version of V8 (3.12.14.0) along with the following changes in the svn log.
      The Pepper Flash Player Plugin has been turned on by default on Mac OSX.
      You can find out how to change to the Dev channel, or any channel, on chromium.org.  If you find a new issue with this release, please shoot us a bug report.
      Anthony Laforge
      Google Chrome

      Beta Channel Update for Chrome OS

      The Beta channel has been updated to 21.0.1180.50 (Platform versions: 2465.82.0) for Chromebooks (Samsung Series 5, Samsung Series 5 550, and Cr-48) and Samsung Chromebox Series 3. This release contains functional, security and stability improvements. Machines will be receiving updates to this version over the next several days.

      Highlights of these changes are:

      • We re-designed the App list to work alongside your browser and apps
      • New connection manager
      • New Print UI - please see the blog post for more details
      • You can select your own custom wallpaper
      • Seccomp Flash sandbox
      • Security fixes

      Known issues:

      • 137273 Connecting to hidden networks fails when you try to connect to it for the first time
      • 31866 Unable to enable mobile data for locked SIM on y3300 and y3400 modems

      • 136864 Multiple options Disabled in the Certificate Manager.

      If you find new issues, please let us know by visiting our
      help site or filing a bug. Interested in switching channels? Find out how. You can submit feedback using ‘Report an issue’ under the wrench menu.

      Josafat Garcia

      Google Chrome

      Friday, July 20, 2012

      Dev Channel Update for Chrome OS


      The Dev channel has been updated to 22.0.1210.0 (Platform versions: 2628.0.0) for Chromebooks (Acer AC700, Samsung Series 5, Samsung Chromebook Series 3, and Cr-48). This build contains a number of UI, stability & security improvements. 

      Highlights of these changes are:

      • Improvements to wifi stability
      • Updated Pepper Flash version

      Known issues:

      • 32766 - Cr-48 machines will go through the out of box sign-up experience after this update, however all data and settings on the machine will be preserved.
      • 138103 - Unable to create a new folder in File Manager

      If you find new issues, please let us know by visiting our help site or filing a bug. Interested in switching channels? Find out how. You can submit feedback using ‘Report an issue’ under the wrench menu.


      Danielle Drew

      Google Chrome

      Wednesday, July 18, 2012

      Beta Channel Update

      The Beta channel has been updated to 21.0.1180.49 for Windows, Mac, Linux and ChromeFrame platforms

      All
      • Several crash fixes (Issues: 134550129446)
      • Fixed Autofill does not work in Incognito mode (Issue: 137100)
      Windows
      • Fixed Legitimate Pop Up is blocked when Pepper Flash is used (Issue: 134959)
      • Fixed Disappearing Tabs On Windows 8 (Issue: 135304)
      Mac
      • Fixed parental controls related problems on mac (Issue: 134311)
      Linux
      • Fixed Chrome never stops blocking power save features once blocked on KDE (Issue: 137538)
      • Fixed Linux users experiencing slowdown due to accessibility being turned on (Issue: 137537)
        More details about additional changes are available in the svn log of all revisions. 

        If you find new issues, please let us know by filing a bug at http://code.google.com/p/chromium/issues/entry

        Karen Grunberg
        Google Chrome

        Monday, July 16, 2012

        Dev Channel Update

        The Dev channel has been updated to 22.0.1207.1 for Windows, Mac, Linux and Chrome Frame. This release contains the following changes:

        All Platforms Windows
        • Fix new installation suffix in [r146217]. Users who installed dev-channel from scratch (i.e. not updating from stable/beta) between July 9th and July 16th might have two Google Chromes show up in “Default Programs” (uninstalling/reinstalling will fix this).
        The full list of changes is available in the svn revision log. You can find out how to change to the Dev channel, or any channel, on chromium.org. If you find a new issue with this release, please shoot us a bug report.

        Jason Kersey
        Google Chrome

        Friday, July 13, 2012

        Dev Channel Updates for Chromebooks

        The Dev channel has been updated to 21.0.1180.41 (Platform versions: 2465.62.0) for Chromebooks (Acer AC700, Samsung Series 5, Samsung Chromebook Series 5 550, Samsung Chromebook Series 3, and Cr-48). This build contains a number of UI, stability & security improvements.

        Highlights of these changes are:

        • Issue with Google Docs (133442)
        • Update Adobe Flash version 11.3.31.218
        • Network Fixes

        Known issues:

        • 137273 Connecting to hidden networks fails when you try to connect to it for the first time
        • 31866 Unable to enable mobile data for locked SIM on y3300 and y3400 modems

        If you find new issues, please let us know by visiting our help site or filing a bug. Interested in switching channels? Find out how. You can submit feedback using ‘Report an issue’ under the wrench menu.

        Josafat Garcia
        Google Chrome

        Thursday, July 12, 2012

        Beta Channel Update


        The Beta channel has been updated to 21.0.1180.41 for Windows, Mac, Linux and ChromeFrame platforms

        All
        Windows
        Mac
        Linux
        • Fixed fullscreen-mode entry and lack of video problem (Issue: 117021)
        More details about additional changes are available in the svn log of all revisions.
        If you find new issues, please let us know by filing a bug at http://code.google.com/p/chromium/issues/entry

        Karen Grunberg
        Google Chrome

        Wednesday, July 11, 2012

        Stable Channel Updates for Chromebooks

        The Google Chrome team is happy to announce the arrival of Chrome 20 to the Stable Channel for ChromeOS.  More detailed updates are available on the Google Blog.  


        The Stable channel has been updated to 20.0.1322.54 (Platform version: 2268.105.0) for Chromebooks (Acer AC700, Samsung Series 5, Samsung Chromebook Series 5 550, and Samsung Chromebox Series 3, and Cr-48). Machines will be receiving updates to this version over the next several days.


        This build contains a number of new features, as well as security & stability improvements.


        Some highlights of these changes are:
        • Support for Google Drive
        • Offline support of Google Docs
        • Firmware update for Chromebook Series 5 550. Note: A screen with Chrome Logo and a critical update notification will show after update restarts. It will reboot by itself after firmware update completes.
        • Updates to Pepper Flash
        • Introduced redesigned UI to Cr-48 systems
        • Switched to open source touchpad driver on Cr-48 systems
        • Crash fixes

        Known issues:
        • 32327 - On Samsung Chromebook Series 5 550, the system may suspend while playing streaming audio.
        • 32420 - There are rare reports of machines where an owner would be required to login to a device before any other user can login. Workaround: If possible, login to the machine as owner. If the owner is unable to login, login to the machine as Guest, and follow the instructions here to download a recovery image and install it on the Chromebook. If you encounter this, please contact our Ninja support group.

        If you find new issues, please let us know by visiting our help site or filing a bug. Interested in switching channels? Find out how. You can submit feedback using ‘Report an issue’ under the wrench menu.

        Danielle Drew
        Google Chrome


        Stable Channel Update

        The Stable channel has been updated to 20.0.1132.57 for Windows, Mac, Linux, and Chrome Frame. Along with below mentioned security fixes, this build contains an update to Flash player, v8 (3.10.8.20) and couple of stability/bug fixes.


        Security fixes and rewards:

        Please see the Chromium security page for more detail. Note that the referenced bugs may be kept private until a majority of our users are up to date with the fix.


        • [$1000] [129898] High CVE-2012-2842: Use-after-free in counter handling. Credit to miaubiz.
        • [$1000] [130595] High CVE-2012-2843: Use-after-free in layout height tracking. Credit to miaubiz.
        • [133450] High CVE-2012-2844: Bad object access with JavaScript in PDF. Credit to Alexey Samsonov of Google.

        Many of these bugs were detected using AddressSanitizer.

        More detailed updates are available on the Chrome Blog.  Full details about what changes are in this release are available in the SVN revision log.  Interested in hopping on the stable channel?  Find out how.  If you find a new issue, please let us know by filing a bug.


        Dharani Govindan
        Google Chrome

        Tuesday, July 10, 2012

        Dev Channel Updates for Chromebooks


        The Dev channel has been updated to 21.0.1180.33 (Platform versions: 2465.55.0) for Chromebooks (Acer AC700, Samsung Series 5, Samsung Chromebook Series 5 550, Samsung Chromebook Series 3, and Cr-48). This build contains a number of UI, stability & security improvements.

        Highlights of these changes are:

        • Fix gtalk crash (133950)
        • Update Adobe Flash
        • Audio Fixes

        Known issues:

        • 133442 "Show Google Docs" malfunctioning

        If you find new issues, please let us know by visiting our help site or filing a bug. Interested in switching channels? Find out how. You can submit feedback using ‘Report an issue’ under the wrench menu.

        Josafat Garcia
        Google Chrome