Tuesday, May 15, 2012

Stable Channel Update


The Google Chrome team is happy to announce the arrival of Chrome 19 to the Stable Channel for Windows, Mac, Linux and Chrome Frame. Chrome 19 contains a number of new features like tab sync. More detailed updates are available on the Chrome Blog.  

Security fixes and rewards:

Please see the Chromium security page for more detail. Note that the referenced bugs may be kept private until a majority of our users are up to date with the fix.
  • [112983] Low CVE-2011-3083: Browser crash with video + FTP. Credit to Aki Helin of OUSPG.
  • [113496] Low CVE-2011-3084: Load links from internal pages in their own process. Credit to Brett Wilson of the Chromium development community.
  • [118374] Medium CVE-2011-3085: UI corruption with long autofilled values. Credit to “psaldorn”.
  • [$1000] [118642] High CVE-2011-3086: Use-after-free with style element. Credit to Arthur Gerkis.
  • [118664] Low CVE-2011-3087: Incorrect window navigation. Credit to Charlie Reis of the Chromium development community.
  • [$500] [120648] Medium CVE-2011-3088: Out-of-bounds read in hairline drawing. Credit to Aki Helin of OUSPG.
  • [$1000] [120711] High CVE-2011-3089: Use-after-free in table handling. Credit to miaubiz.
  • [$500] [121223] Medium CVE-2011-3090: Race condition with workers. Credit to Arthur Gerkis.
  • [121734] High CVE-2011-3091: Use-after-free with indexed DB. Credit to Google Chrome Security Team (Inferno).
  • [$1000] [122337] High CVE-2011-3092: Invalid write in v8 regex. Credit to Christian Holler.
  • [$500] [122585] Medium CVE-2011-3093: Out-of-bounds read in glyph handling. Credit to miaubiz.
  • [122586] Medium CVE-2011-3094: Out-of-bounds read in Tibetan handling. Credit to miaubiz.
  • [$1000] [123481] High CVE-2011-3095: Out-of-bounds write in OGG container. Credit to Hannu Heikkinen.
  • [Linux only] [123530] Low CVE-2011-3096: Use-after-free in GTK omnibox handling. Credit to Arthur Gerkis.
  • [123733] [124182] High CVE-2011-3097: Out-of-bounds write in sampled functions with PDF. Credit to Kostya Serebryany of Google and Evgeniy Stepanov of Google.
  • [Windows only] [124216] Low CVE-2011-3098: Bad search path for Windows Media Player plug-in. Credit to Haifei Li of Microsoft and MSVR (MSVR:159).
  • [124479] High CVE-2011-3099: Use-after-free in PDF with corrupt font encoding name. Credit to Mateusz Jurczyk of Google Security Team and Gynvael Coldwind of Google Security Team.
  • [124652] Medium CVE-2011-3100: Out-of-bounds read drawing dash paths. Credit to Google Chrome Security Team (Inferno).

And some additional rewards for issues with a wider scope than Chrome:

  • [Linux only] [$500] [118970] Medium CVE-2011-3101: Work around Linux Nvidia driver bug. Credit to Aki Helin of OUSPG.
  • [$1500] [125462] High CVE-2011-3102: Off-by-one out-of-bounds write in libxml. Credit to Jüri Aedla.

Many of the above bugs were detected using AddressSanitizer.

We’d also like to thank Aki Helin of OUSPG, Sławomir Błażek, Chamal de Silva, miaubiz, Arthur Gerkis and Christian Holler for working with us during the development cycle and preventing security regressions from ever reaching the stable channel. $9000 of additional rewards were issued for this awesomeness.



Full details about what changes are in this release are available in the SVN revision log.  Interested in hopping on the stable channel?  Find out how.  If you find a new issue, please let us know by filing a bug.

Anthony Laforge
Google Chrome

41 comments:

Carl said...

wow.. i think the new chrome is blazing fast... thanks for chrome team hardwork. And, if i can say a suggestion, please make a new chrome with new look interface.. thanks..

Ramo 1 said...

Celebrity Young:pop culture, celebrities, tv, cinema, entertainment, and more recent photos, news and gossip! The currentMagazine Site ...

Ramo 1 said...

Trend Film izle Yeni çıkan yerli ve yabancı filmleri indirmeden online ve full izleyebileceğiniz sinema platformudur...

Rafael said...

The back pages to catch while being loaded and I roll our costs and our lock to unlock it again Pack your please had been resolved more now returned.

Rafael said...

The pages are also in another language are not translated are constantly giving server error.

duuude said...

Awesome! Thanks guys.

The only thing that really stinks is that since updating from 18, smooth scrolling isn't working at all on Windows. (While it didn't work *everywhere* in 17 and 18, it worked fine in most places [I'd say about 9/10] for me.)

Cody said...

I love the speed improvement and uber page, but I have a few suggestions:

(1) Make the uber page main navigation text ("settings, "history"...) larger and separated from the main frame. I am looking forward to more sections (like bookmarks).

(2) Redesign the NTP to remove clutter and the need to navigate between sections. Because Most Visited and Apps are separated, many users probably only use one section. For a design mock, see Issue 119907. Also, there should only be 1 Web Store links.

(3) I am still looking forward to the redesigned downloads UI. I suggest a tabbed design.

Rafael said...

The new tab page is taking too long to open in version 19 of Google Chrome Final.

fikrishare.com said...

amazing, chrome 19 super speed. thanks.

Emannxx said...

Smooth scrolling is not working (Windows 7 x64). Please fix it ASAP.

HAMAD ALRASHIDI said...

startup google chrome no more default homepage , if you go to settings and set "On startup" open specific page to google.com its work but ...
it will only be for the first chrome window that you open if you open a second chrome window it just fail and open a "New Tab page" even with incognito window , not to mention the bad new settings page i really miss the old one , i notes delay in startup and high cpu usage whenever i open new chrome window

HAMAD ALRASHIDI said...

Whoa! Google Chrome had crashed. Relaunch now?

Whoa! Google Chrome had crashed. Relaunch now?

Whoa! Google Chrome had crashed. Relaunch now?

Whoa! Google Chrome had crashed. Relaunch now?

Whoa! Google Chrome had crashed. Relaunch now?

Whoa! Google Chrome had crashed. Relaunch now?

Whoa! Google Chrome had crashed. Relaunch now?

Whoa! Google Chrome had crashed. Relaunch now?

Whoa! Google Chrome had crashed. Relaunch now?

i just opened 3 chrome windows 1 google.com and the 2 3 new tabs close close close

Whoa! Google Chrome had crashed. Relaunch now?
Whoa! Google Chrome had crashed. Relaunch now?
Whoa! Google Chrome had crashed. Relaunch now?
Whoa! Google Chrome had crashed. Relaunch now?
Whoa! Google Chrome had crashed. Relaunch now?

Scrogginsanity said...

Smooth scrolling is not working at all (Windows 7). Bummer!

Unknown said...

Not only is smooth scrolling not working on Windows 7, but I also lost the ability to use the mouse wheel button to close tabs. It's a difficult habit to get out of, and I'd like it back please.

Michael Hart said...

Unknown, my middle mouse button is working just fine at closing tabs.

Michael Hart said...

What makes me most sad: No API for tabs sync. It essentially makes it useless for over a million Chrome users who don't use the stock new tab page.

Mike Hendrix said...

Smooth Scrolling still works, just not with the mouse scroll wheel.

Mainman678 said...

On setting remember pages open each time I close the browser to try to remember I get an error for it where it wont remember it. All it tells me google chrome didn't shutdown properly and I click restore button to get them back. Sometimes it will give me another error where it shows my google account is not signed in. Then I relaunch browser and I am signed in again. Please fix this google chrome.

Scoty said...

Roboform no longer work with the new final build 19.

Mirek said...

Chrome toolbox and other extensions that use doubleclick to close tabo or mose wheel to move through tabs are not working! I think also mouse gesture extensions stopped working.

cpm said...
This comment has been removed by the author.
cpm said...
This comment has been removed by the author.
cpm said...

So after the Update a URL with

http://user:password@aaa.bbb.cc

did not work anymore. Any hints?

Hannibal said...

showing up "old flash player" all the time (debian x64). I have to manually allow each time, if want to watch a video etc. whats wrong there? or is it a new feature?!

visachris said...

Do best, no regret. It is said that wholesale oakley sunglasses is a good business, so I concern on oakley sunglasses 2012 and oakley sunglasses clearance.

gstevens said...

Keep getting this message now:

Google Chrome had crashed. Relaunch now?

AAAAAAH, cant live without Chrome!!

offramps said...

Freezing a lot! Keep havin to shut down laptop.

HAMAD ALRASHIDI said...

launch first chrome window takes 5 sec why why the delay why why why

Ramesh Iyer said...

Any particular reason folks at Chrome have started listing Dev channel updates and then Stable channel updates since past few versions (after ver. 17, I think) ?

It is so much easier for Chrome users to check changes in Stable channel if listed right on top. Hope Google changes this hereafter.

HAMAD ALRASHIDI said...

Whoa! Google Chrome had crashed. Relaunch now?

Whoa! Google Chrome had crashed. Relaunch now?

Whoa! Google Chrome had crashed. Relaunch now?

Whoa! Google Chrome had crashed. Relaunch now?

Whoa! Google Chrome had crashed. Relaunch now?

Whoa! Google Chrome had crashed. Relaunch now?

HAMAD ALRASHIDI said...

Your profile could not be opened correctly.

Some features may be unavailable. Please check that the profile exists and you have permission to read and write its contents.

Your profile could not be opened correctly.

Some features may be unavailable. Please check that the profile exists and you have permission to read and write its contents.

Your profile could not be opened correctly.

Some features may be unavailable. Please check that the profile exists and you have permission to read and write its contents.

Your profile could not be opened correctly.

Some features may be unavailable. Please check that the profile exists and you have permission to read and write its contents.

Your profile could not be opened correctly.

Some features may be unavailable. Please check that the profile exists and you have permission to read and write its contents.

Lauraine said...

hanks for sharing your info. I really appreciate your efforts and I will be waiting for your further write ups thanks once again.
html5 media player| youtube html5 player

William said...
This comment has been removed by the author.
William said...

It would be useful to know the actual version number of this release, e.g 19.x.x.x

Benjamin said...

At my workplace we set the homepage to an important site that our users need to log into. This update removed the home page, creating quite a few calls and work for our help desk. I feel this is the sort of thing that should never be be altered. That the new settings page obscures the home page setting is inconvenient, but not too bad. It seems like these changes are an attempt to alter user behavior, but for what reason I do not know.

chotisri@gmail.com said...

Guys & Gals,

You did a great job this time. This is the first build that I could right click any cache link and not get an "Error" message! It took quite some time (up to Build 19!), but you finally pulled it off. Please don't screw this up. Keep up the good work!

chotisri@gmail.com

Matt said...

Hi,

Did you change somewhere the way javascript handles Date objects when used as keys in object literals? It seems that previous to v19 getTime() was implicity called (as it is on other browsers), but isn't any more? I couldn't see anything in the logs.

I was using this: it worked fine on 18, and broke as soon as I hit the 'update' button...

I'm not sure it's a bug, mainly just curious.

Thanks

Matt Parker

Lequebecois said...

I can't reactivate the Adobe pdf viewer, even if the adobe pdf viewer is activated (in Chrome plugins windows), pdf files open with Google pdf viewer (your PDF viewer really sucks)

Dave Nielsen said...

Due to an odd corporate setup, the only way I'm able to update Chrome is by following the instructions here:
http://productforums.google.com/d/msg/chrome/n-kFBeCRbw0/DjPGaKXI6EUJ

These instructions require the last two numbers in the four-number Chrome version number, which is usually posted in these posts.

Can you please post the complete, four-number version number for this Stable Chrome release?

Thanks!

Peter said...

Why is Java 7 not used in Google Chrome 19 ?

Ninotix said...

19.0.1084.46 is final and stable version number of Chrome 19