Chrome 155 release includes HTTPS-First mode and support for JPEG XL format

Google has released version 155 of the Chrome web browser. At the same time, a stable release of the open-source project Chromium, which serves as the foundation for Chrome, is also available. The Chrome browser differs from Chromium in its use of Google logos, a system for sending crash notifications, modules for playing protected video content (DRM), an automatic updates installation system, continuous Sandbox isolation, provision of keys to the Google API, and transmission of RLZ parameters during searches. For those who need more time to update, an Extended Stable branch is maintained separately, accompanied by an 8-week support period. The next release, Chrome 156, is scheduled for October 20 within the new bi-weekly development cycle.

Key changes in Chrome 155 (1, 2, 3, 4):

  • The 'HTTPS-First' feature is enabled by default for all users, automatically redirecting HTTP requests to HTTPS for publicly accessible sites that aren't hosted on intranet networks, such as 192.168.0.1/16 and 10.0.0.0/8. To ensure compatibility with sites that do not support HTTPS, a fallback to HTTP is implemented if a request cannot be fulfilled via HTTPS after redirection, or if there are certificate issues. When attempting to open a site via HTTP, a special warning message is displayed.
  • JPEG XL image decoding support is enabled by default. The implementation is based on the jxl-rs library, written in Rust. JPEG XL allows for a file size reduction of 30-50% compared to JPEG images of equivalent quality. Supported advanced features include: HDR, animation, transparency, progressive loading mode, smooth degradation of quality with reduced bitrate, lossless JPEG compression, support for up to 4099 channels, and a wide range of color depths.
  • The visual design of the profile creation interface has been updated (the functionality remains unchanged). For Windows, a new onboarding stage for profile creation has been added, which will be shown at the first launch of the browser (for Linux and macOS, it will appear in Chrome version 158).
  • The range of devices that can interact via the WebHID API has been expanded, intended for low-level access to HID devices (Human Interface Device, such as keyboards, mice, gamepads, touchpads) and to facilitate operation without specific drivers in the system.
  • In the chrome://extensions page of the extensions management menu, a new option has been added for rating and writing reviews for installed extensions, which redirects to the corresponding pages in the Chrome Web Store catalog upon clicking.
  • The media-playback-while-not-visible permission has been implemented, allowing the blocking of audio and video playback within embedded iframes when they are not in the visible area.
  • The CSS property margin-trim has been added, enabling the removal of margins before the first and after the last element within a parent container.
  • The CSS property text-decoration-skip-spaces has been added, controlling the display of decorators (such as underlining or strikethrough) under spaces in text.
  • The CSS function symbols() has been added for simplifying the customization of using non-standard markers in lists.
  • The WebCrypto API has added support for cryptographic algorithms resistant to quantum computer attacks — ML-KEM and ML-DSA, as well as the ChaCha20-Poly1305 and X-Wing algorithms.
  • The Window Management API has added new window control methods: maximize(), minimize(), and restore() for expanding the window to full screen, minimizing or restoring it to its previous size. A method setResizable() has also been added to control the ability to manually resize the window. CSS media queries display-state and resizable have been added to determine if the window is minimized or expanded, and whether it can be resized.
  • New built-in color spaces (PredefinedColorSpace) have been added — srgb-linear and display-p3-linear.
  • Support for text modules imported using the 'import … with { type: "text" }' construct has been added.

In addition to new features and bug fixes, the new version addresses 247 vulnerabilities. Four issues have been assigned a critical severity level, indicating that these vulnerabilities allow bypassing all browser security measures and executing code on the system outside the sandbox environment. All critical issues are caused by accessing already freed memory (use-after-free).

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster