Jump to content

Recommended Posts

Posted (edited)

portatil-google-chrome.jpg

 

The Chrome web browser has the most significant market share of them all, with 3.45 billion users, so it’s not surprising that many eyes are on the code looking for security flaws. Google has just released version 129 of Chrome, fixing nine security vulnerabilities, and users are urged to update as soon as possible. Here’s what you need to know.

 
 

What’s New In Google Chrome ?

What's new in Chrome 133

Energy Saver Mode

One percent of users now benefit from a feature that freezes tabs in energy saver mode. If a tab consumes significant CPU resources and remains hidden for over five minutes, it gets frozen automatically.

Chrome Sync Update

Chrome Sync no longer supports versions older than four years. To store and sync browser data linked to a Google account across systems, users must use at least Chrome 89.

Android JIT Optimizer Setting

The Android version introduces a new setting that allows users to disable JIT optimizers in the V8 JavaScript engine. Disabling JIT can improve the security of potentially dangerous web apps by reducing possible attack vectors. On desktop versions, this setting is available in chrome://settings/security since Chrome 122.

URL Parsing Standardization

Chrome now follows a standard for parsing non-special URL schemes like "git://example.com/path".

WebAssembly Memory64 Support

WebAssembly gained the ability to use 64-bit pointers (Memory64), enabling work with linear memory areas larger than 4 GB.

Developer Tools Enhancements

The web developer tools have received updates, including saving your AI-powered chat history across sessions and a new “What’s new?” panel that summarizes the changes in the latest version.

Vulnerability Fixes

Finally, in addition to introducing new features and fixing bugs, Chrome 133 fixed twelve vulnerabilities. Automated testing tools such as AddressSanitizer, MemorySanitizer, Control Flow Integrity, LibFuzzer, and AFL helped identify many of these issues. Two issues related to accessing freed memory in the V8 engine and Skia library received high severity ratings. No critical issues allowing sandbox bypass or system-level code execution were found. As part of its vulnerability bounty program, Google awarded two bounties totaling $9,000 for this release ($7,000 and $2,000). The amount of one bounty remains unspecified.

Edited by 大†Shinegumi†大
Posted

The Stable channel has been updated to 132.0.6834.110/111 for Windows, Mac and 132.0.6834.110 for Linux which will roll out over the coming days/weeks. A full list of changes in this build is available in the Log.

The extended stable channel has been updated to 132.0.6834.110/111( Windows, Mac) and will roll out over the coming days/weeks.

 

Security Fixes and Rewards

Note: Access to bug details and links may be kept restricted until a majority of users are updated with a fix. We will also retain restrictions if the bug exists in a third party library that other projects similarly depend on, but haven’t yet fixed.

 

This update includes 3 security fixes. Below, we highlight fixes that were contributed by external researchers. Please see the Chrome Security Page for more information.

 

[$11000][386143468] High CVE-2025-0611: Object corruption in V8. Reported by 303f06e3 on 2024-12-26

[$8000][385155406] High CVE-2025-0612: Out of bounds memory access in V8.Reported by Alan Goodman on 2024-12-20

 

We would also like to thank all security researchers that worked with us during the development cycle to prevent security bugs from ever reaching the stable channel.

As usual, our ongoing internal security work was responsible for a wide range of fixes:

  • [391144311] Various fixes from internal audits, fuzzing and other initiatives

 


Many of our security bugs are detected using AddressSanitizer, MemorySanitizer,UndefinedBehaviorSanitizer, Control Flow Integrity, libFuzzer, or AFL.

 

 

 

Interested in switching release channels? Find out how here. If you find a new issue, please let us know by filing a bug. The community help forum is also a great place to reach out for help or learn about common issues.


 

 

Daniel Yip

Google Chrome

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

×
×
  • Create New...