Release of Chrome 104

Google has released version 104 of the Chrome web browser. At the same time, a stable release of the open-source project Chromium, which forms the basis of Chrome, is also available. Chrome differs from Chromium in its use of Google logos, a notification system for crashes, modules for playing DRM-protected video content, an automatic update installation system, continuous Sandbox isolation, the provision of keys to Google APIs, and the transmission of RLZ parameters during searches. For those who need more time to update, the Extended Stable branch is supported separately, with an 8-week duration. The next release, Chrome 105, is scheduled for August 30.

Key changes in Chrome 104:

  • A maximum lifespan for Cookies has been introduced—all new or updated Cookies will be automatically deleted after 400 days of existence, even if the expiration time set through the Expires and Max-Age attributes exceeds 400 days (for such Cookies, the lifespan will be shortened to 400 days). Cookies created before the implementation of the limit will retain their lifespan, even if it exceeds 400 days; however, they will be limited upon updates. This change reflects new requirements noted in a draft of the new specification.
  • Requests from iframes to URLs referencing the local file system ("filesystem://") are now blocked.
  • A new optimization has been added to speed up page loading by establishing a connection to the target host at the moment a link is clicked, without waiting for the button to be released or the finger to be lifted from the touchscreen.
  • Settings have been added to manage the Topics & Interest Group API, promoted under the Privacy Sandbox initiative, which allows defining user interest categories and using them instead of tracking Cookies to group users with similar interests without identifying individual users. In addition, one-time information dialogs have been added to explain the technology to users and offer to activate its support in the settings.
  • The threshold values for limiting nested calls to setTimeout and setInterval timers, initiated with an interval of less than 4 ms ("setTimeout(…, <4ms)") have been increased. The total limit on such calls has been raised from 5 to 100, allowing for aggressive non-trimming of individual calls, while preventing abuses that could impact browser performance.
  • The server of the main site now includes a request for CORS (Cross-Origin Resource Sharing) authority confirmation with the header "Access-Control-Request-Private-Network: true" when accessing a subresource in the internal network (192.168.x.x, 10.x.x.x, 172.16-31.x.x) or to localhost (127.x.x.x). When confirming the operation in response to this request, the server must return the header "Access-Control-Allow-Private-Network: true". In version Chrome 104, the result of confirmation does not yet affect request handling — if confirmation is absent, a warning is displayed in the web console, but the subresource request is not blocked. Enabling blocking in the absence of confirmation server is expected no earlier than in Chrome 107. To enable blocking in earlier versions, you can activate the setting "chrome://flags/#private-network-access-respect-preflight-results".

    Authorization confirmation proxy server has been introduced to enhance protection against attacks related to resource access in the local network or on the user's computer (localhost) from scripts loaded when the site is opened. Such requests are leveraged by attackers to carry out CSRF attacks on routers, access points, printers, corporate web interfaces, and other devices and services that accept requests only from the local network. To protect against such attacks, when accessing any subresources in the internal network, the browser will send an explicit request for the authority to load these subresources.

  • A Region Capture mechanism has been added, allowing the trimming of unnecessary content from video generated based on screen capture. For instance, using the getDisplayMedia API, a web application can facilitate video streaming containing tab content, and Region Capture allows for cutting out portions of that content that include video conference controls.
  • Support has been added for a specific new syntax of media queries defined in the Media Queries Level 4 specification, which defines the minimum and maximum size of the viewport. The new syntax allows the use of standard comparison and logical operators such as 'not', 'or', and 'and'. For example, instead of '@media (min-width: 400px) { … }', you can now specify '@media (width >= 400px) { … }'.
  • Several new APIs have been added in Origin Trials (experimental features that require separate activation). Origin Trials allow the specified API to be used from applications loaded from localhost or 127.0.0.1, or after registration and obtaining a special token, which is valid for a limited time for a specific site.
    • A new CSS property 'focusgroup' has been added to enhance navigation through elements using keyboard arrow keys.
    • The Secure Payment Confirmation API now provides users with the option to disable the storage of credit card details. To display a dialog allowing users to opt-out of saving credit card details, the 'showOptOut: true' flag is included in the PaymentRequest() constructor.
    • The Shared Element Transitions API has been introduced, allowing for smooth transitions between different content views in single-page web applications.
  • Support for speculation rules has been stabilized, enabling authors to provide browsers with information about the most likely pages a user may navigate to. Browsers use this information for preloading and rendering page content.
  • The mechanism for packaging subresources into Web Bundle format has been stabilized, increasing the efficiency of loading a large number of related files (CSS styles, JavaScript, images, iframes). Unlike Webpack bundles, the Web Bundle format has the following advantages: only its components, not the bundle itself, are stored in the HTTP cache; JavaScript compilation and execution begin without waiting for the full bundle to load; additional resources such as CSS and images can be included, which in webpack had to be encoded as JavaScript strings.
  • The CSS property object-view-box has been added, allowing you to define part of an image that will be displayed in the area instead of the specified element, which can be used, for example, to add a border or shadow.
  • The Fullscreen Capability Delegation API has been introduced, allowing one Window object to delegate the right to call requestFullscreen() to another Window object.
  • The Fullscreen Companion Window API has been added, allowing fullscreen content and pop-ups to be displayed on another screen after user confirmation.
  • The CSS property overflow-clip-margin has been enhanced with a visual-box attribute that indicates where the clipping of overflow content should start (it can accept values of content-box, padding-box, and border-box).
  • The Async Clipboard API now allows the identification of specialized formats for data transferred through the clipboard that differ from text, images, and markup text.
  • WebGL now supports specifying the color space for the framebuffer and transformations when importing from textures.
  • Support for OS X 10.11 and macOS 10.12 has been discontinued.
  • Support for the U2F API (Cryptotoken), which was previously deprecated and disabled by default, has been dropped. The Web Authentication API has replaced the U2F API.
  • Improvements have been made to web development tools. The debugger now includes the ability to restart code from the beginning of a function after a breakpoint is hit somewhere within the function. Support for developing plugins for the Recorder panel has been added. The performance analysis panel now includes support for visualizing markers set in the web application through the performance.measure() method call. Recommendations for autocompleting JavaScript object properties have been enhanced. A preview of CSS variable values not related to colors is provided during autocompletion.
    Release of Chrome 104

In addition to new features and bug fixes, the new version addresses 27 vulnerabilities. Many of the vulnerabilities were identified through automated testing tools such as AddressSanitizer, MemorySanitizer, Control Flow Integrity, LibFuzzer, and AFL. No critical issues that would allow an escape from all browser protection levels to execute code outside of the sandbox environment were found. As part of the vulnerability reward program for this release, Google has paid out 22 rewards totaling $84,000 (one reward of $15,000, one of $10,000, one of $8,000, one of $7,000, four of $5,000, one of $4,000, three of $3,000, four of $2,000, and three of $1,000). The amount of one reward has not yet been determined.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster