<?xml version="1.0" encoding="UTF-8"?> <rss
version="2.0"
xmlns:content="http://purl.org/rss/1.0/modules/content/"
xmlns:wfw="http://wellformedweb.org/CommentAPI/"
xmlns:dc="http://purl.org/dc/elements/1.1/"
xmlns:atom="http://www.w3.org/2005/Atom"
xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
> <channel><title>gHacks Technology News &#124; Latest Tech News, Software And Tutorials &#187; chrome security</title> <atom:link href="http://www.ghacks.net/tag/chrome-security/feed/" rel="self" type="application/rss+xml" /><link>http://www.ghacks.net</link> <description>A technology news blog covering software, mobile phones, gadgets, security, the Internet and other relevant areas.</description> <lastBuildDate>Sat, 11 Feb 2012 17:32:23 +0000</lastBuildDate> <language>en</language> <sy:updatePeriod>hourly</sy:updatePeriod> <sy:updateFrequency>1</sy:updateFrequency> <generator>http://wordpress.org/?v=3.3.1</generator> <atom:link rel="hub" href="http://pubsubhubbub.appspot.com"/><atom:link rel="hub" href="http://superfeedr.com/hubbub"/> <item><title>Google Chrome Stable Updated To 12</title><link>http://www.ghacks.net/2011/06/07/google-chrome-stable-updated-to-12/</link> <comments>http://www.ghacks.net/2011/06/07/google-chrome-stable-updated-to-12/#comments</comments> <pubDate>Tue, 07 Jun 2011 17:01:49 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[Browsing]]></category> <category><![CDATA[Google Chrome]]></category> <category><![CDATA[chrome security]]></category> <category><![CDATA[google browser]]></category> <category><![CDATA[google chrome]]></category> <category><![CDATA[google chrome stable]]></category> <guid
isPermaLink="false">http://www.ghacks.net/?p=46195</guid> <description><![CDATA[Google has updated the stable channel of the Google Chrome web browser. The Chrome browser is now at version 12.0.742.91 on the stable channel. The new release combines security fixes, other updates and even a few new features that have been added to that version that have previously only been available on the other channels. [...]]]></description> <content:encoded><![CDATA[<p>Google has updated the stable channel of the Google Chrome web browser. The Chrome browser is now at version 12.0.742.91 on the stable channel. The new release combines security fixes, other updates and even a few new features that have been added to that version that have previously only been available on the other channels.</p><p>Lets take a look at the feature updates and additions first. Chrome Stable now supports 3D CS and launching apps from the Chrome address bar by simply typing in their name. Apps are web apps that are installed at the Chrome web store.</p><p>Probably more interesting than those two features is the ability to delete Flash cookies directly from within the browser, by clearing the browsing history. This was previously not possible and improves the privacy of the user significantly.</p><p>Another new security related feature is the new safe browsing protection that protects the user better from downloading malicious files.</p><p>The data synchronization service Google Sync is now integrated into the Chrome settings page, which users can access by clicking on the wrench icon and selecting options from the context menu.</p><ul><li>[73962] [79746] High CVE-2011-1808: Use-after-free due to integer issues in float handling.</li><li>[75496] Medium CVE-2011-1809: Use-after-free in accessibility support.</li><li>[75643] Low CVE-2011-1810: Visit history information leak in CSS.</li><li>[76034] Low CVE-2011-1811: Browser crash with lots of form submissions.</li><li>[77026] Medium CVE-2011-1812: Extensions permission bypass.</li><li>[78516] High CVE-2011-1813: Stale pointer in extension framework.</li><li>[79362] Medium CVE-2011-1814: Read from uninitialized pointer.</li><li>[79862] Low CVE-2011-1815: Extension script injection into new tab page.</li><li>[80358] Medium CVE-2011-1816: Use-after-free in developer tools.</li><li>[81916] Medium CVE-2011-1817: Browser memory corruption in history deletion.</li><li>[81949] High CVE-2011-1818: Use-after-free in image loader.</li><li>[83010] Medium CVE-2011-1819: Extension injection into chrome:// pages.</li><li>[83275] High CVE-2011-2332: Same origin bypass in v8.</li><li>[83743] High CVE-2011-2342: Same origin bypass in DOM.</li></ul><p>All information about the stable channel update is available over at the <a
href="http://googlechromereleases.blogspot.com/2011/06/chrome-stable-release.html?utm_source=feedburner&#038;utm_medium=feed&#038;utm_campaign=Feed%3A+GoogleChromeReleases+%28Google+Chrome+Releases%29">Chrome blog</a>. Chrome should already pick up the new release. New users can download <a
href="http://www.google.com/chrome/intl/en/make/download.html?brand=CHKZ">Chrome 12</a> from the official Chrome project website.</p> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2011/06/07/google-chrome-stable-updated-to-12/feed/</wfw:commentRss> <slash:comments>1</slash:comments> </item> <item><title>Google Chrome Stable Security Update 11.0.696.68 Released</title><link>http://www.ghacks.net/2011/05/12/google-chrome-stable-security-update-11-0-696-68-released/</link> <comments>http://www.ghacks.net/2011/05/12/google-chrome-stable-security-update-11-0-696-68-released/#comments</comments> <pubDate>Thu, 12 May 2011 19:04:33 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[Browsing]]></category> <category><![CDATA[Google Chrome]]></category> <category><![CDATA[Chrome]]></category> <category><![CDATA[chrome security]]></category> <category><![CDATA[chrome stable]]></category> <category><![CDATA[chrome update]]></category> <category><![CDATA[google chrome stable]]></category> <guid
isPermaLink="false">http://www.ghacks.net/?p=45082</guid> <description><![CDATA[Google has just released an update for the stable branch of Google Chrome that brings the version of the web browser to 11.0.696.68. The update, which is available for Microsoft Windows, Apple Macintosh, Linux and Chrome Frame platforms is a security update that fixes two security vulnerabilities in Chrome. Both security issues that have been [...]]]></description> <content:encoded><![CDATA[<p>Google has just released an update for the stable branch of Google Chrome that brings the version of the web browser to 11.0.696.68. The update, which is available for Microsoft Windows, Apple Macintosh, Linux and Chrome Frame platforms is a security update that fixes two security vulnerabilities in Chrome.</p><p>Both security issues that have been fixed by the developers have received a rating of high, the second highest severity rating available.</p><ul><li>[64046] High CVE-2011-1799: Bad casts in Chromium WebKit glue.</li><li>[80608] High CVE-2011-1800: Integer overflows in SVG filters.</li></ul><p>The new Chrome stable version additionally contains Adobe&#8217;s Flash Player 10.3, which has been updated to that version. While it is not explicitly mentioned on the Google Chrome Releases blog, it seems as if that version is a final build of Adobe Flash Player 10.3 and not the release candidate.</p><p>The final version has not yet been officially released by Adobe. It would not be the first time that Google, thanks to the direct tie-in of Flash Player in Chrome, managed to update Flash Player ahead of time.</p><p>The long awaited <a
href="http://www.ghacks.net/2011/03/08/a-close-look-at-adobe-flash-player-10-3-beta/">Flash Player 10.3</a> adds several new features to the popular software, most noticeably an option to delete so called Flash cookies from within the browser.</p><p>Google Chrome Stable users should get update notifications soon, if they have not already. Users who <a
href="http://www.google.com/chrome/intl/en/make/download.html?brand=CHKZ">prefer to</a> download Chrome from the official website can do that as well. The browser can be updated by running the installer after the download has finished.</p> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2011/05/12/google-chrome-stable-security-update-11-0-696-68-released/feed/</wfw:commentRss> <slash:comments>2</slash:comments> </item> <item><title>Google Chrome Security Update Released</title><link>http://www.ghacks.net/2011/03/25/google-chrome-security-update-released/</link> <comments>http://www.ghacks.net/2011/03/25/google-chrome-security-update-released/#comments</comments> <pubDate>Fri, 25 Mar 2011 10:38:59 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[Browsing]]></category> <category><![CDATA[Google Chrome]]></category> <category><![CDATA[chrome security]]></category> <category><![CDATA[google chrome]]></category> <category><![CDATA[google chrome update]]></category> <guid
isPermaLink="false">http://www.ghacks.net/?p=43050</guid> <description><![CDATA[Google yesterday released a security update for the Google Chrome web browser that brings the version of the browser to 10.0.648.204. The update is as usually installed via automatic updates on most Google Chrome installations. Chrome users who have automatic updates disabled can check for new updates under the Tools icon > About Google Chrome [...]]]></description> <content:encoded><![CDATA[<p>Google yesterday released a security update for the Google Chrome web browser that brings the version of the browser to 10.0.648.204. The update is as usually installed via automatic updates on most Google Chrome installations. Chrome users who have automatic updates disabled can check for new updates under the Tools icon > About Google Chrome option.</p><p>The update is available for all supported operating systems (Microsoft Windows, Linux and Apple Macintosh) as well as Chrome Frame, a plugin for Microsoft&#8217;s Internet Explorer that allows Internet Explorer users to utilize Chrome&#8217;s rendering engine in the Microsoft browser.</p><p>A total of six security issues have been fixed in the new version of Google Chrome, of which all have received a severity rating of high, the second highest rating.</p><ul><li>CVE-2011-1291: Buffer error in base string handling.</li><li>CVE-2011-1292: Use-after-free in the frame loader.</li><li>CVE-2011-1293: Use-after-free in HTMLCollection.</li><li>CVE-2011-1294: Stale pointer in CSS handling.</li><li>CVE-2011-1295: DOM tree corruption with broken node parentage.</li><li>CVE-2011-1296: Stale pointer in SVG text handling.</li></ul><p>The update has been rolled out for the stable channel of the browser, but it is likely that the security fixes have been fixed in beta, dev and canary builds as well previously.</p><p>Some Chrome users are reporting crashes related to the Flash plugin on sites such as Gmail or the Irish RTE. (<a
href="http://googlechromereleases.blogspot.com/2011/03/stable-channel-update.html?utm_source=feedburner&#038;utm_medium=feed&#038;utm_campaign=Feed%3A+GoogleChromeReleases+%28Google+Chrome+Releases%29">via</a>)</p><p>In other news: The Chrome Dev channel has been updated as well to version 12.0.712.0 on all supported operating systems. The update is not a security update though. It adds multi-tab selection to the browser and updates the V8 rendering engine to 3.2.3.1. Mac users get &#8220;new and improved bookmark bar animations&#8221;. (<a
href="http://googlechromereleases.blogspot.com/2011/03/dev-channel-update_24.html">via</a>)</p> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2011/03/25/google-chrome-security-update-released/feed/</wfw:commentRss> <slash:comments>3</slash:comments> </item> <item><title>Google Chrome 4 (Stable) Security Fixes</title><link>http://www.ghacks.net/2010/03/17/google-chrome-4-stable-security-fixes/</link> <comments>http://www.ghacks.net/2010/03/17/google-chrome-4-stable-security-fixes/#comments</comments> <pubDate>Wed, 17 Mar 2010 17:23:38 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[Browsing]]></category> <category><![CDATA[Google Chrome]]></category> <category><![CDATA[chrome security]]></category> <category><![CDATA[google chrome]]></category> <category><![CDATA[google chrome security]]></category> <guid
isPermaLink="false">http://www.ghacks.net/?p=23782</guid> <description><![CDATA[The Google Chrome developers have just released a new version of Google Chrome 4 that fixes several security issues in the Windows client. Users who have Google Chrome 4 installed are encouraged to update their web browser as soon as possible to protect it from possible exploits targeting those security vulnerabilities. The Google Chrome Releases [...]]]></description> <content:encoded><![CDATA[<p>The Google Chrome developers have just released a new version of Google Chrome 4 that fixes several security issues in the Windows client. Users who have Google Chrome 4 installed are encouraged to update their web browser as soon as possible to protect it from possible exploits targeting those security vulnerabilities.</p><p>The Google Chrome Releases blog lists a total of nine security vulnerabilities that have been fixed in the latest stable release of the web browser.</p><p><span
id="more-23782"></span><br
/><blockquote><li>High Race conditions and pointer errors in the sandbox infrastructure.Credit to Mark Dowd, under contract to Google Chrome Security Team.</li><li>Low Delete persisted metadata such as Web Databases and STS.Credit to Google Chrome Security Team (Chris Evans) and RSnake of ha.ckers.org.</li><li>Medium HTTP headers processed before SafeBrowsing check.Credit to Mike Dougherty of dotSyntax, LLC.</li><li>High Memory error with malformed SVG.Credit to wushi of team509.</li><li>High Integer overflows in WebKit JavaScript objects.Credit to Sergey Glazunov.</li><li>Medium HTTP basic auth dialog URL truncation.Credit to Google Chrome Security Team (Inferno).</li><li>Medium Bypass of download warning dialog.Credit to kuzzcc.</li><li>High Cross-origin bypass.Credit to kuzzcc.</li><li>High Memory error with empty SVG element.Credit to Aki Helin of OUSPG.</li></blockquote><p>Google is still running the monetary compensation program for developers who find security vulnerabilities in the web browser.</p><p>The developers have also disabled the experimental anti-reflected-XSS feature called &#8220;XSS Auditor&#8221; in this release as it caused serious performance issues in some rare cases.</p><p>The latest version of Google Chrome can be downloaded directly from the <a
href="http://www.google.com/chrome">official</a> Google website.</p> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2010/03/17/google-chrome-4-stable-security-fixes/feed/</wfw:commentRss> <slash:comments>1</slash:comments> </item> <item><title>Chrome Password Recovery Tool</title><link>http://www.ghacks.net/2009/02/22/chrome-password-recovery-tool/</link> <comments>http://www.ghacks.net/2009/02/22/chrome-password-recovery-tool/#comments</comments> <pubDate>Sun, 22 Feb 2009 09:30:49 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[Browsing]]></category> <category><![CDATA[Google Chrome]]></category> <category><![CDATA[Chrome]]></category> <category><![CDATA[chrome browser]]></category> <category><![CDATA[chrome pass]]></category> <category><![CDATA[chrome password]]></category> <category><![CDATA[chrome password recovery]]></category> <category><![CDATA[chrome passwords]]></category> <category><![CDATA[chrome security]]></category> <category><![CDATA[google chrome]]></category> <guid
isPermaLink="false">http://www.ghacks.net/?p=10692</guid> <description><![CDATA[ChromePass is a portable application that has been created by one of our favorite software developers Nirsoft. Its purpose is to provide the means to recover passwords that have been saved in the Chrome web browser. Chrome, like most web browsers, provides the means to store login information to access websites faster on consecutive visits. [...]]]></description> <content:encoded><![CDATA[<p><a
href="http://www.nirsoft.net/utils/chromepass.html">ChromePass</a> is a portable application that has been created by one of our favorite software developers Nirsoft. Its purpose is to provide the means to recover passwords that have been saved in the Chrome web browser. Chrome, like most web browsers, provides the means to store login information to access websites faster on consecutive visits.</p><p>ChromPass can be started from any location including removable drives which makes it an excellent password recovery tool. It will automatically fetch the information upon startup and display them in a list. Included in these information are the username, password, url and even the time the entry has been created.</p><p>The login details can be exported in various formats including html, csv or xml file.</p><p><span
id="more-10692"></span><img
src="http://www.ghacks.net/wp-content/uploads/2009/02/chromepass-500x153.gif" alt="chromepass" title="chromepass" width="500" height="153" class="alignnone size-medium wp-image-10693" /></p><p>The password recovery tool comes with an additional option to load the passwords from another user of the local computer, the logon password has to be supplied though to make this possible. One of the greatest security weaknesses is the lack of a master password. It would be impossible to use a tool like ChromePass if a master password would have been set.</p> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2009/02/22/chrome-password-recovery-tool/feed/</wfw:commentRss> <slash:comments>3</slash:comments> </item> </channel> </rss>
