Release of Chrome 96

Google has released the web browser Chrome 96. At the same time, a stable version of the open-source project Chromium, which serves as the foundation for Chrome, is available. The Chrome browser is distinguished by its use of Google logos, a notification system for crash reports, modules for playing protected video content (DRM), an automatic update system, and the transmission of RLZ parameters during searches. The Chrome 96 branch will be supported for 8 weeks within the Extended Stable cycle. The next release, Chrome 97, is scheduled for January 4.

Key changes in Chrome 96:

  • The bookmarks bar, displayed under the address bar, has hidden the Apps button by default, which allowed users to open the 'chrome://apps' page with a list of installed services and web applications.
    Release of Chrome 96
  • Support for Android 5.0 and earlier versions has been discontinued.
  • Support for redirecting from HTTP to HTTPS using DNS has been added (when determining (the key to connect to is specified, and iroh finds the associated host and establishes an encrypted connection using the QUIC protocol). Direct P2P connections are established whenever possible, but if not, it falls back to using relays, which are also employed for host discovery by keys. You can run your own relay or connect to public relays supported by the community. in addition to DNS records 'A' and 'AAAA', the DNS record 'HTTPS' is also requested, allowing the browser to connect to the site via HTTPS immediately if it exists).
  • In the desktop version, the back-forward cache, which provides instantaneous transitions when using the 'Back' and 'Forward' buttons, now supports navigation to previously viewed pages after opening a different site.
  • A setting 'chrome://flags#force-major-version-to-100' has been added for testing potential website malfunctions after the browser reaches a version consisting of three digits instead of two (back when Chrome 10 was released, many issues arose in User-Agent parsing libraries). When activated, the User-Agent header will return version 100 (Chrome/100.0.4664.45).
  • In builds for the Windows platform, data related to network services (cookies, etc.) has been moved to a separate 'Network' subdirectory in preparation for implementing network isolation mechanisms (Network Sandbox).
  • Several new APIs have been added in Origin Trials (experimental features that require separate activation). Origin Trials allow the specified API to be used from applications loaded from localhost or 127.0.0.1, or after registration and obtaining a special token, which is valid for a limited time for a specific site.
    • A FocusableMediaStreamTrack object (to be renamed to BrowserCaptureMediaStreamTrack) has been proposed, supporting the focus() method, which allows applications capturing window or tab content (such as programs streaming window content during video conferences) to receive input focus information and track changes.
    • A Priority Hints mechanism has been implemented, allowing the importance of resources being loaded to be specified using an additional "importance" attribute in tags such as iframe, img, and link. The attribute can take the values "auto", "low", and "high", which influence the order in which the browser loads external resources.
  • Support for the "credentialless" parameter has been added to the Cross-Origin-Embedder-Policy header, which governs Cross-Origin isolation mode and allows the specification of safe usage rules for privileged operations on the page by disabling the transmission of credential-related information, such as cookies and client certificates.
  • A new pseudo-class ":autofill" has been proposed in CSS to track when fields in the input tag are automatically filled by the browser (the selector does not trigger during manual filling).
  • To prevent request loops, the CSS properties writing-mode, direction, and backgrounds now do not apply to the viewport when using the CSS contain property on HTML or BODY tags.
  • A new CSS property font-synthesis has been added, allowing control over the synthesis of styles (oblique, bold, and small-cap) that are absent in the selected font family.
  • In the PerformanceEventTiming API, which provides additional information for measuring and optimizing interface responsiveness, the InteractionID attribute has been added to identify user interactions. This identifier allows different metrics to be linked to a single user action, for example, when touching a touchscreen, multiple events such as pointerdown, mousedown, pointerup, mouseup, and click are generated, and InteractionID allows all these events to be connected to a single touch.
  • A new type of media query, "prefers-contrast", has been added for adapting the content of the page to the contrast settings set in the operating system (for example, enabling high contrast mode).
  • For standalone PWA applications, support for an optional "id" field has been added to the manifest, with a global application identifier (if the field is not specified, the starting URL is used for identification).
  • Standalone PWA applications now have the capability to register as URL handlers. For example, the application music.example.com can register itself as the handler for the URL https://*.music.example.com, and all transitions from external applications using these links, such as from messengers and email clients, will lead to opening this PWA application instead of a new tab in the browser.
  • The CSP (Content Security Policy) directive wasm-unsafe-eval has been added to control the ability to execute code on WebAssembly. The application of the CSP directive script-src now also covers WebAssembly.
  • WebAssembly has added support for reference types (externref type). WebAssembly modules can now store and pass references to JavaScript and DOM objects as arguments.
  • The PaymentMethodData has deprecated support for the 'basic-card' payment method, which allowed working with any card types through a single identifier, regardless of specific data types. Instead of 'basic-card', it is recommended to use alternative methods such as Google Pay, Apple Pay, and Samsung Pay.
  • When using the U2F API (Cryptotoken), users will see a warning about the deprecation of this API. The U2F API will be disabled by default in Chrome 98 and completely removed in Chrome 104. The Web Authentication API should be used instead of the U2F API.
  • Improvements have been made to web developer tools. A new 'CSS Overview' panel has been added, providing a summary of information about colors, fonts, unused declarations, and media queries, as well as highlighting potential issues. Editing and copying operations for CSS have been improved. In the Styles panel, a context menu option has been added for copying CSS definitions as JavaScript expressions. The network request inspection panel has introduced a Payload tab for parsing request parameters. In the web console, an option to hide all CORS (Cross-Origin Resource Sharing) errors has been added, and stack tracing for async functions has been enabled.
    Release of Chrome 96

In addition to new features and bug fixes, the new version addresses 25 vulnerabilities. Many vulnerabilities were identified through automated testing using AddressSanitizer, MemorySanitizer, Control Flow Integrity, LibFuzzer, and AFL tools. No critical issues have been found that would allow bypassing all browser security levels and executing code in the system outside of the sandbox environment. As part of the bug bounty program for this release, Google has awarded 13 prizes totaling $60,000 (one prize of $15,000, one prize of $10,000, two prizes of $7,500, one prize of $5,000, two prizes of $3,000, one prize of $2,500, two prizes of $2,000, two prizes of $1,000, and one prize of $500). The size of 5 rewards has not yet been determined.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster