Release of Chrome 145

Google has released version 145 of the Chrome web browser. The stable release of the free project Chromium, which serves as the foundation for Chrome, is also available. Chrome differs from Chromium in its use of Google logos, the presence of a crash reporting system, modules for playing protected video content (DRM), an automatic update installation system, continuous Sandbox isolation, the provision of keys to the Google API, and the transmission of RLZ parameters during searches. For those who need more time to update, an Extended Stable branch is separately maintained, supported for 8 weeks. The next Chrome release, version 146, is scheduled for March 10.

Key changes in Chrome 145:

  • Support for the JPEG XL image format has been added, for which the jxl-rs library implementing JPEG-XL in the Rust language is utilized. JPEG XL support is currently disabled by default and requires activating the parameter "chrome://flags/#enable-jxl-image-format."
  • Development of the AI mode continues, allowing interaction with an AI agent from the address bar or from the page displayed when opening a new tab. The AI mode enables users to ask complex questions in natural language and receive answers based on aggregating information from the most relevant pages on the given topic. If necessary, users can clarify information with follow-up questions. The mode also allows questions about the content of the page directly from the address bar. In Chrome 145, the AI mode is implemented in the versions for Android and iOS platforms. For users in Canada, India, and New Zealand, the Gemini chatbot has begun to be enabled by default (when using English).
  • A mechanism for DBSC (Device Bound Session Credentials) has been introduced, allowing the session authentication on the site to be tied to a specific device, complicating attacks from other systems using intercepted session cookies. To create a device-bound session, the HTTP header "Secure-Session-Registration" is proposed. The protection method involves providing a pair of cryptographic keys tied to the current device, generated upon connection and stored in the TPM (Trusted Platform Module). Short-lived cookies that are periodically updated using a private key and verifiable with a public key are used in the session.
    Release of Chrome 145
  • The option to disable the enforcement of browser extensions that violate minor rules of the Chrome Web Store directory has been removed. Minor violations include the presence of potential vulnerabilities, imposing the extension without user consent, manipulating metadata, violating user data handling rules, and misleading users about functionality.
  • In the version for the Android platform, when the Advanced Protection Mode (AAPM) is activated, the JavaScript API WebGPU is disabled. Websites using WebGPU for rendering 3D content (e.g., Google Maps) may utilize slower alternatives like WebGL (which tests show to be 5.78% slower). To determine the disabling of WebGPU, the property navigator.gpu can be used.
  • In the Android version, when the Enhanced Safe Browsing feature is enabled, local analysis of the appearance of pages for signs of fraud is implemented. If the local check raises suspicions of dubious content, an additional verification on Google servers is performed, and if confirmed, a warning is issued to the user.
  • The Origin API has been added, providing an Origin object that implements the Web Origin concept and offers methods for comparing, serializing, and parsing Web Origin. The term 'Web Origin' is defined in RFC 6454 for dividing boundaries of isolation and trust in content. Web Origin encompasses part of the URL, including the protocol name, host name, and port number (e.g., https://opennet.ru). This new API has been introduced to unify operations with Web Origin and eliminate vulnerabilities due to incorrect comparisons of serialized ASCII representations of Web Origin when determining resource affiliation to a single site.
  • Access rights to the local system have been separated when interacting with public websites. Requests from the site to IP addresses the local network (intranet or internal addresses) and the loopback interface (127.0.0.0/8) are now processed using different privileges (local-network and loopback-network), requiring user confirmation in a special dialog for the operation. The protection measures apply to attempts to load resources, fetch() requests, and iframe insertions. Access to internal resources is exploited by attackers to carry out CSRF attacks on routers, access points, printers, corporate web interfaces, and other devices and services that only accept requests from the local network. Additionally, scanning internal resources can be used for indirect identification or gathering information about the local network.
  • The UserAgentReduction setting has been removed, which allowed the transmission of untrimmed information in the HTTP User-Agent header and JavaScript parameters navigator.userAgent, navigator.appVersion, and navigator.platform. The browser now always sends a trimmed version of the User-Agent without detailed platform information (e.g., 'Android 16; S' instead of 'Android 16; SM-A205U').
  • The built-in PDF viewer has been enhanced to allow saving documents to Google Drive cloud storage. In Google Drive, documents from Chrome are saved in the 'Saved from Chrome' folder.
  • The LayoutShift API, which allows tracking changes in the position of DOM elements on the screen, has been modified to output information in CSS pixels instead of screen pixels. CSS pixels take the screen DPI into account and appear visually consistent across all screens, including high-density pixel monitors. This change was made to align Chrome's behavior with that of other browsers.
  • The API Controlled Frame implements the WebRequest.SecurityInfo method, allowing web applications to intercept HTTPS, WSS, or WebTransport requests to the server, obtaining a snapshot of the certificate. server and use it for manual verification of the certificate used for direct connections to the same server via TCP/UDP.
  • Support has been added for the CSS properties column-wrap and column-height, defined in the CSS Multi-column Layout 2 specification. The column-wrap property allows columns to move to a new line instead of horizontal scrolling when the columns do not fit within the height specified by column-height.
  • A new CSS property text-justify has been added, allowing for the definition of text alignment type when using "text-align: justify";
  • In the CSS properties letter-spacing and word-spacing, it is now allowed to specify the spacing size in percentages.
  • In JavaScript objects Map and WeakMap, the "upsert" specification has been implemented, simplifying work with collections of key/value pairs. New methods getOrInsert and getOrInsertComputed return an existing value in the collection associated with the specified key or create a new entry if the key is not found.
  • The IndexedDB API implementation has been rewritten using the SQLite database as a backend (the previous implementation was based on LevelDB in separate files). The new version is currently used only in contexts hosted in memory, for example, it is applied in incognito mode.
  • Improvements have been made to the tools for web developers. In the network inspection interface, the "Request conditions" panel now includes by default the ability to limit the speed of individual network requests.

In addition to new features and bug fixes, the new version addresses 11 vulnerabilities. Many of the vulnerabilities were identified through automated testing using AddressSanitizer, MemorySanitizer, Control Flow Integrity, LibFuzzer, and AFL. No critical issues allowing circumvention of all browser protection levels and execution of code in the system outside the sandbox environment were found. As part of the vulnerability reward program for this release, Google has established 11 awards and paid out $18,500 (including one award of $8000, $5000, $2000, and $500, and three awards of $1000). The amounts for 4 rewards have yet to be determined.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster