Chrome 101 Release

Google has launched the release of the Chrome 101 web browser. At the same time, a stable release of the open-source project Chromium, which serves as the basis for Chrome, is available. The Chrome browser differs from Chromium by using Google logos, having a crash notification system, modules for playing copy-protected video content (DRM), an automatic update installation system, constant Sandbox isolation, provision of keys for Google APIs, and passing RLZ parameters during search. For those who need more time for updates, a separate Extended Stable branch is available, supported for 8 weeks, where an update for the previous Chrome 100 release has been created. The next release, Chrome 102, is scheduled for May 24.

Key changes in Chrome 101:

  • A Side Search feature has been added, allowing users to view search results in a sidebar while simultaneously browsing another page (the same window can display both page content and search results). After navigating to a site from the Google search results page, an icon with the letter 'G' appears before the address bar; clicking it opens a sidebar with results from the previous search. By default, this feature is not enabled on all systems; it can be activated using the setting 'chrome://flags/#side-search'.
    Chrome 101 Release
  • In the Omnibox address bar, proactive rendering has been implemented for the recommendations provided as users type. Previously, to speed up transitions from the address bar, the most likely recommendations were preloaded without waiting for a user click, using a Prefetch call. Now, in addition to loading, they are also rendered in the buffer (including running scripts and forming the DOM tree), allowing for instant display of recommendations after a click. Configuration options for proactive rendering are offered at 'chrome://flags/#enable-prerender2', 'chrome://flags/#omnibox-trigger-for-prerender2', and 'chrome://flags/#search-suggestion-for-prerender2'.
  • Information in the HTTP header User-Agent and JavaScript parameters navigator.userAgent, navigator.appVersion, and navigator.platform has been trimmed. The header now only includes details about the browser name, major browser version (with MINOR.BUILD.PATCH version components replaced with 0.0.0), platform, and device type (mobile phone, PC, tablet). To obtain additional data, such as the exact version and extended platform data, the User Agent Client Hints API must be used. For sites that find this new information insufficient and are not yet ready to transition to User Agent Client Hints, the option to return the full User-Agent will be available until May 2023.
  • The behavior of the setTimeout function has been changed when passing a zero argument for the delay. Starting with Chrome 101, when specifying 'setTimeout(…, 0)', the code will be executed immediately, without the 1ms delay stipulated by the specification. For nested calls to setTimeout, a delay of 4ms will be applied.
  • Support for requesting notification permissions has been implemented in the Android platform version (in Android 13, to display notifications, the app must have the 'POST_NOTIFICATIONS' permission; without it, notifications will be blocked). When running Chrome in an Android 13 environment, the browser will now prompt for notification permission.
  • The use of the WebSQL API in third-party scripts has been removed. By default, blocking WebSQL in scripts loaded from non-current sites was enabled in Chrome 97, but an option was provided to disable this behavior. In Chrome 101, that option has been removed. Further plans are to gradually discontinue support for WebSQL entirely, regardless of the context of use. It is recommended to use the Web Storage API and Indexed Database instead of WebSQL. The WebSQL handler is based on SQLite code and could have been exploited by attackers to take advantage of vulnerabilities in SQLite.
  • Policy names for enterprises (chrome://policy) containing non-inclusive terms have been removed. Starting with Chrome 86, inclusive terminology replacements have been offered for the specified policies. Terms such as 'whitelist', 'blacklist', 'native', and 'master' have been cleaned up. For instance, the URLBlacklist policy has been renamed to URLBlocklist, AutoplayWhitelist to AutoplayAllowlist, and NativePrinters to Printers.
  • The Origin Trials mode (experimental features requiring separate activation) has begun testing the Federated Credential Management API (FedCM) only in builds for the Android platform, allowing the creation of unified identification services that ensure privacy and operate without cross-site tracking mechanisms such as third-party cookie handling. The Origin Trial allows for interaction with the specified API from applications loaded from localhost or 127.0.0.1, or after registration and obtaining a special token valid for a limited time for a specific site.
  • The Priority Hints mechanism has been stabilized and is now available to everyone, allowing the importance of a resource being loaded to be specified by using an additional 'importance' attribute in tags such as iframe, img, and link. The attribute can take the values 'auto', 'low', and 'high', which affect the order in which the browser loads external resources.
  • The AudioContext.outputLatency property has been added, which provides information about the expected latency before sound output (the delay between the sound request and the start of processing the received data by the sound output device).
  • The CSS property font-palette and the @font-palette-values rule have been added, allowing the selection of a palette from a colored font or the definition of a custom palette. For example, this feature can be used to match colored symbolic fonts or emojis to the color scheme of content or to enable dark or light mode for the font.
  • The CSS function hwb() has been added, providing an alternative method for specifying colors in the sRGB format in HWB (Hue, Whiteness, Blackness), a format similar to HSL (Hue, Saturation, Lightness) but easier for human perception.
  • In the window.open() method, specifying the popup property in the windowFeatures string without assigning a value (i.e., when popup is simply indicated, not popup=true) is now treated as enabling the opening of a thumbnail popup window (similar to popup=true) instead of defaulting to false, which was illogical and misleading for developers.
  • The MediaCapabilities API, which provides information about the device and browser's abilities to decode multimedia content (supported codecs, profiles, bitrates, and resolutions), has added support for WebRTC streams.
  • The third version of the Secure Payment Confirmation API, which provides tools for additional confirmation of payment transactions, has been proposed. The new version includes support for identifiers that require input, icon determination for indicating verification failure, and an optional property payeeName.
  • The USBDevice API has added the forget() method to revoke previously granted user permissions for accessing the USB device. Additionally, instances of USBConfiguration, USBInterface, USBAlternateInterface, and USBEndpoint are now equal in strict comparison (===, pointing to the same object) if returned for the same USBDevice object.
  • Improvements have been made to web developer tools. The ability to import and export user actions recorded in JSON format has been provided (example). In the web console and code inspection interface, the calculation and display of private properties have been enhanced. Support for the HWB color model has been added. The CSS panel now includes the ability to view cascading layers specified with the @layer rule.
    Chrome 101 Release

In addition to new features and bug fixes, the new version resolves 30 vulnerabilities. Many of the vulnerabilities were identified through automated testing using tools such as AddressSanitizer, MemorySanitizer, Control Flow Integrity, LibFuzzer, and AFL. No critical issues were found that would allow bypassing all levels of browser protection and executing code on the system outside of the sandbox environment. As part of the bug bounty program for this release, Google has awarded 25 prizes totaling $81,000 (one prize of $10,000, three prizes of $7,500, three prizes of $7,000, one prize of $6,000, two prizes of $5,000, four prizes of $2,000, three prizes of $1,000, and one prize of $500). The amount of 6 prizes has yet to be determined.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster