Chrome 103 Release

Google has released version 103 of its web browser Chrome. At the same time, a stable release of the open-source project Chromium, which is the foundation of Chrome, is available. The Chrome browser differs from Chromium in that it uses Google logos, has a crash notification system, modules for playing protected content (DRM), an automatic update system, always-on sandbox isolation, provides keys to the Google API, and passes RLZ parameters during searches. For those who need more time to update, an Extended Stable branch is maintained separately and is supported for 8 weeks. The next release of Chrome 104 is scheduled for August 2.

Key changes in Chrome 103:

  • An experimental image editor has been added, which can be called up to edit screenshots of pages. The editor includes features such as cropping, area selection, brush drawing, color picking, adding text labels, and generating standard shapes and primitives like lines, rectangles, circles, and arrows. To enable the editor, the settings "chrome://flags/#sharing-desktop-screenshots" and "chrome://flags/#sharing-desktop-screenshots-edit" need to be activated. After creating a screenshot through the Share menu in the address bar, the editor can be accessed by clicking the "Edit" button on the screenshot preview page.
    Chrome 103 Release
  • The capabilities of the pre-rendering mechanism added in Chrome 101 have been expanded to render recommendation content in the Omnibox address bar. Pre-rendering complements the previously available feature of loading the most likely recommendations for navigation without waiting for user clicks. In addition to loading, the content of pages related to recommendations can now be pre-rendered in the buffer (including executing scripts and constructing the DOM tree), allowing for instant display of recommendations after clicking. Settings offered for managing pre-rendering include "chrome://flags/#enable-prerender2", "chrome://flags/#omnibox-trigger-for-prerender2", and "chrome://flags/#search-suggestion-for-prerender2".

    In Chrome 103 for Android, the Speculations Rules API has been added, allowing website authors to convey information about the most likely pages the user may navigate to. The browser uses this information to pre-load and render the content of these pages.

  • The Android version features a new password manager that offers the same unified password management interface as used in Android applications.
  • Support for the 'With Google' service has been added to the Android version, enabling users to express gratitude to their favorite registered websites by sending paid or free digital stickers. This service is currently available only to users in the USA.
    Chrome 103 Release
  • Autofill for credit and debit card fields has been improved, now supporting cards saved via Google Pay.
  • The Windows version now uses a built-in DNS client by default, which is also utilized in the versions for macOS, Android, and Chrome OS.
  • The Local Font Access API has been stabilized and made available to all, allowing users to identify and use fonts installed on their systems, as well as manipulate fonts at a low level (for instance, filtering and transforming glyphs).
  • Support for the HTTP response code 103 has been added, which allows notifying the client about the contents of certain HTTP headers immediately after the request, without waiting for the server to complete all operations related to the request and begin delivering content. server This way, hints about resources related to the served page can be communicated, which may be pre-loaded (for example, links to CSS and JavaScript used on the page). Once the browser receives information about such resources, it can start loading them without waiting for the main page to finish delivering, reducing the overall request processing time.
  • The Origin Trials mode (experimental features requiring separate activation) has begun testing the Federated Credential Management API (FedCM) only in builds for the Android platform, allowing the creation of unified identification services that ensure privacy and operate without cross-site tracking mechanisms such as third-party cookie handling. The Origin Trial allows for interaction with the specified API from applications loaded from localhost or 127.0.0.1, or after registration and obtaining a special token valid for a limited time for a specific site.
  • In the Client Hints API, being developed as a replacement for the User-Agent header and allowing selective delivery of data about specific browser and system parameters (version, platform, etc.) only after a request. proxy server, the ability to substitute fictitious names into the browser identifier list has been added, similar to the GREASE (Generate Random Extensions And Sustain Extensibility) mechanism used in TLS. For example, in addition to ‘”Chrome”; v=“103”‘ and ‘”Chromium”; v=“103”‘, a random identifier for a non-existent browser ‘” (Not;Browser”; v=“12”‘ can be added to the list. This substitution will help identify issues with processing identifiers of unknown browsers, which leads alternative browsers to masquerade as other popular browsers to bypass the validation against the allowed browser list.
  • AVIF image files have been added to the list of allowed formats for exchange via the iWeb Share API.
  • Support for the ‘deflate-raw’ compression format has been added, which allows access to the raw compressed stream without headers and auxiliary final blocks, which can be used, for example, for reading and writing zip files.
  • For web form elements, it is now possible to use the ‘rel’ attribute, which allows applying the ‘rel=noreferrer’ parameter for navigation through web forms to disable the transmission of the Referer header or ‘rel=noopener’ to disable setting the Window.opener property and restrict access to the context from which the transition was made.
  • The implementation of the popstate event has been aligned with Firefox behavior. The popstate event is now generated immediately after the URL changes without waiting for the load event.
  • For pages opened without HTTPS and from iframe blocks, access to the Gamepad API and Battery Status API is prohibited.
  • The SerialPort object has added a forget() method to revoke previously granted user permissions for accessing the serial port.
  • The CSS overflow-clip-margin property has added the visual-box attribute, which defines where the clipping of content that exceeds the boundary of the area should start (it can take values content-box, padding-box, and border-box).
  • In iframe blocks with the sandbox attribute, calling external protocols and launching external handler applications is prohibited. To lift the restriction, the allow-popups, allow-top-navigation, and allow-top-navigation-with-user-activation properties should be used.
  • Support for the element has been discontinued, which has lost its meaning after the end of plugin support.
  • Improvements have been made to the tools for web developers. For instance, the Styles panel now allows defining the color of a point outside the browser window. The preview of parameter values in the debugger has been enhanced. The ability to change the order of panels in the Elements interface has been added.

In addition to new features and bug fixes, the latest version has addressed 14 vulnerabilities. Many of these vulnerabilities were identified through automated testing using tools like AddressSanitizer, MemorySanitizer, Control Flow Integrity, LibFuzzer, and AFL. One issue (CVE-2022-2156) has been assigned a critical severity level, which implies the potential to bypass all layers of browser protection and execute code on the system outside the sandbox environment. Details regarding this vulnerability have not yet been disclosed; it is only known that it is caused by accessing a freed memory block (use-after-free).

As part of the bug bounty program for the current release, Google awarded 9 prizes totaling $44,000 (one prize of $20,000, one prize of $7,500, one prize of $7,000, two prizes of $3,000, and one prize each of $2,000, $1,000, and $500). The amount for rewarding critical vulnerabilities has not been determined yet.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster