Release of web browser Chrome 137

Google has released the web browser Chrome 137. At the same time, a stable release of the open-source project Chromium, which is the foundation of Chrome, is also available. Chrome differs from Chromium by using Google logos, having a notification system for crashes, modules for playing protected video content (DRM), an automatic update installation system, always-on Sandbox isolation, providing keys for Google API, and transmitting RLZ parameters during search requests. For those who need more time to update, a separate Extended Stable branch is maintained, accompanied by 8 weeks of support. The next release, Chrome 138, is scheduled for June 24.

Key changes in Chrome 137:

  • The Windows and macOS builds have integrated the Gemini chatbot, which can explain the content of the viewed page and answer related questions without switching tabs. Text and voice interactions with Gemini are supported. Currently, the chatbot is available only to a subset of users in the US who have Google AI Pro and Ultra subscriptions.
  • Similar to the previously implemented storage segmentation, isolation of the processing of the scheme URL 'blob:' has been ensured, designed for access to locally generated data through the Blob or File API. When segmenting, a separate attribute is attached to the key used to retrieve objects, defining the binding to the primary domain, from which the main page was opened, allowing the blocking of methods that track user movement between sites through manipulation of the URL 'blob:'.
  • In Enhanced protection mode of the browser (Safe Browsing > Enhanced protection), the ability to use a large language model to identify fraudulent pages by their content has been activated. The AI model runs on the client side, but in cases where suspicious content is detected, an additional check is performed on servers Google. In the current version, only information is being gathered about problematic pages. The next release plans to start issuing warnings to users.
  • Protection against hidden user identification is enabled using HSTS (HTTP Strict Transport Security) caching. HSTS allows websites to redirect users to HTTPS when accessing via HTTP. During its operation, the hostname set via HSTS is stored in an internal cache, which enables the use of the presence or absence of the hostname in the cache to store a single bit of information. For secretly storing a 32-bit user identifier, an array of 32 images served from different hosts via HTTP (http://bit0.example.com/image.jpg, http://bit1.example.com/image.jpg, etc.) can be used. The identifier is determined by checking from which hosts the images were loaded via HTTPS and which via HTTP (if the images were previously served via HTTP and redirected to HTTPS through HSTS, they will immediately be loaded via HTTPS on subsequent requests, bypassing the HTTP request). The protection comes down to allowing HSTS updates only for top-level resources and blocking HSTS updates in subresource requests.
  • Support for the DTLS 1.3 protocol (Datagram Transport Layer Security, analogous to TLS for UDP) has been implemented for WebRTC connections. DTLS 1.3 support is necessary for using post-quantum encryption algorithms in WebRTC.
  • The command-line option ‘—load-extension’ has been removed, which allowed for extensions to be loaded. This option was removed to reduce the risk of its use for injecting malicious extensions. To force the loading of unpacked extensions, it is recommended to use the 'Load Unpacked' button on the extensions management page (chrome://extensions/) after enabling developer mode. Support for the ‘—load-extension’ option has been retained in Chromium and testing builds of Chrome For Testing.
  • It has been decided to discontinue the automatic fallback to the use of the SwiftShader software rendering system for WebGL, which implements the Vulkan API. In the absence of a proper GPU-based backend, creating a WebGL context will now return an error instead of switching to SwiftShader. The discontinuation of SwiftShader will enhance security by eliminating the execution of code generated by the JIT compiler in the process responsible for GPU interaction. A separate command-line option "--enable-unsafe-swiftshader" is available to revert to using SwiftShader. In Chrome version 137, for Linux and macOS users, a warning will be displayed in the web console when using SwiftShader, and in Chrome 138, the rollback to SwiftShader will be disabled. For Windows users, the SwiftShader system has been replaced with the built-in Windows rendering system WARP (Windows Advanced Rasterization Platform).
  • A new feature "Autofill with AI" has been added to the settings, simplifying the filling out of web forms. When enabled, the browser uses an AI model to understand the web form and automatically fill in fields based on how the user previously filled out similar forms.
  • The Web Cryptography API has added support for cryptographic algorithms based on the elliptic curve Curve25519, such as the Ed25519 digital signature algorithm.
  • The CSS property "reading-flow" has been implemented, allowing for control over the processing order of elements in flex, grid, and block containers when using screen readers and during sequential navigation. The "reading-order" property has also been added, enabling manual overriding of the order of elements.
  • A new function "if()" has been proposed in CSS, designed to select values based on the outcome of conditional expressions. It takes a semicolon-separated list of pairs "condition:value" as an argument. The function iterates through these pairs and stops at the first matching condition. For example: "background-color: if(style(—color: white): black; else: white);".
  • The offset-path CSS property has been implemented with the shape() function for forming shapes using commands equivalent to the path() function, but allowing the use of standard CSS syntax.
  • The JSPI (JavaScript Promise Integration) API has been added, allowing integration of WebAssembly applications with the JavaScript Promise object and enabling WebAssembly programs to act as Promise generators and interact with Promise-based APIs.
  • Support for pixel formats using floating-point values to represent color components has been added to the CanvasRenderingContext2D, OffscreenCanvasRenderingContext2D, and ImageData APIs.
  • Experimental APIs Rewriter and Writer have been offered in the Origin Trials, allowing for rewriting (e.g., summarizing or changing narrative style) or generating text using large language models.
  • The web development tools now include workspace binding capabilities, enabling the saving of changes made to JavaScript, HTML, and CSS in local files when using the browser's built-in tools. The AI assistant's capabilities have been expanded to modify CSS and analyze performance.

In addition to new features and bug fixes, the latest version resolves 1 vulnerability. Many vulnerabilities were identified through automated testing tools including AddressSanitizer, MemorySanitizer, Control Flow Integrity, LibFuzzer, and AFL. No critical issues allowing circumvention of all browser security levels and code execution outside the sandbox environment were found. As part of the bug bounty program for the current release, Google has awarded 8 prizes totaling $7,500 (one prize of $4,000, $2,000, $1,000, and $500). The amount for four prizes has yet to be determined.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster