Chrome 154 Release

Google has released version 154 of the Chrome web browser. At the same time, a stable release of the open-source project Chromium, which serves as the foundation for Chrome, is available. Chrome differs from Chromium in that it uses Google logos, includes a crash reporting system, has modules for playing copy-protected video content (DRM), features automatic update installation, always includes Sandbox isolation, comes with access keys for Google APIs, and transmits RLZ parameters during searches. For those who need more time to update, the Extended Stable branch is separately supported for 8 weeks. The next release, Chrome 155, is scheduled for October 6 as part of a new two-week development cycle.

Key changes in Chrome 154 (1, 2, 3, 4):

  • The development of the AI mode continues, allowing interaction with the AI assistant from the address bar or the page displayed when opening a new tab. In the new version, users in the US can use the AI assistant Gemini for virtual clothing fitting while shopping at certain online stores. Chrome for iOS has implemented support for real-time voice communication with Gemini, for example, to discuss the content of an open web page.
  • Programming interfaces and technologies developed under the Privacy Sandbox initiative, intended to replace third-party cookies, have been removed. The rationale for supplying these APIs was lost after the decision not to discontinue third-party cookie support in Chrome. The following APIs have been removed: Topics (which replaced the FLoC API), Protected Audience API, Shared Storage API, Attribution Reporting API, Private Aggregation, Related Website Sets API, and requestStorageAccessFor.
  • In the Android version, the LNP (Local Network Protection) mode has been activated, which requires separate confirmation for an application to access internal intranet subnets (192.168.x.x, 10.x.x.x, etc.). This mode helps block attacks on local network resources and prevents network scans aimed at covertly identifying the user and gathering information about their environment.
  • To make API Background Fetch requests, LNA (Local Network Access) permissions are now required when sending data to servers in the local network (192.168.0.0/16, 10.0.0.0/8, etc.) or when accessing the loopback interface (127.0.0.0/8). Additionally, CORS (Cross-Origin Resource Sharing) checks have been applied to the API Background Fetch to unify restrictions imposed on both API Background Fetch and Fetch. These changes block the use of Background Fetch to bypass Cross-Origin restrictions and carry out CSRF attacks on routers, access points, printers, corporate web interfaces, and other devices and services that only accept requests from the local network.
  • An optional optimization mode called "ServiceWorkerAutoPreload" has been added, which sends a network request in parallel with the initialization of the Service Worker.
  • The HTML element and the JavaScript API Web Install (method navigator.install()) have been introduced to prompt users for the installation of a web application. Installation occurs only after the user explicitly confirms the operation. This feature can be utilized when creating app store directories or to simplify the installation of web applications for use with the current site.
  • The Window Shape API (method window.setShape) has been added, allowing isolated web applications to change the window shape, such as creating non-rectangular windows, floating panels, and overlapping elements. This API is currently available only on ChromeOS.
  • Settings have been added to manage the types of content for which autofill will be applied in web forms. For example, it is possible to disable saving and autofilling contact information and payment details. URL templates can also be configured to disable autofill for specific sites.
  • By default, a confirmation request prompt is enabled when accessing sites over HTTP.
  • Support has been added for adaptive iframe block size selection, automatically adjusting to content to eliminate internal scroll bars. This feature can be enabled by specifying the CSS property "frame-sizing" (e.g., "frame-sizing: content-height") on the parent page and adding the following meta tag in the iframe header: '<meta name="responsive-embedded-sizing" content="allow-origins=*">'.
  • The CSS property scroll-marker-group has been implemented with modes "links" and "tabs" for controlling the order of focus switching. In the "links" mode, the marker group ("::scroll-marker-group") acts like a regular navigation menu (scroll markers are handled like links navigable by the Tab key). In "tabs" mode, the marker group behaves like a set of tabs, with navigation between them handled by the control keys. Additionally, there are two parameters, "before" and "after", to manage the handling of the marker group relative to content (specifying "before" means markers will be processed first, while "after" means only after navigating through content).
  • The CSS property text-decoration-inset has been implemented, allowing for the configuration of the start and end points of the rendering of decorators (underlines, strikethroughs, etc.) relative to the text edges. For example, to shorten the decorator by 10 pixels, you can specify "text-decoration-inset: 10px;" and to extend it, use "text-decoration-inset: -10px;".
  • In the JavaScript Iterator interface, the method Iterator.prototype.includes has been added to check for the presence of a specific element in the iterator.
  • In the "Origin trials" mode, the Private Verification Tokens (PVT) mechanism has been implemented, which allows distinguishing real users from bots by transmitting anonymous tokens when opening websites in private browsing mode, thus eliminating the need for CAPTCHA requests, mandatory authentication, and tracking via Cookies. The tokens reflect successful authentication or anti-bot checks previously completed (checks already passed on one site can be used to connect to other sites without further verification).

In addition to new features and bug fixes, the new version addresses 108 vulnerabilities. 11 of these issues have been assigned a critical level of severity, indicating that the vulnerabilities allow bypassing all levels of browser protection and executing code in the system outside of the sandbox environment. 4 critical issues are caused by use-after-free memory access in AdFilter, WindowDialog, ServiceWorker, and the Fullscreen API, while 7 are due to buffer overflows in WebGL, ANGLE, and GPU handling code.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster