Google Inc. release of the web browser . At the same time, the stable release of the open-source project , which serves as the foundation for Chrome. The Chrome browser features the use of Google logos, a crash notification system, the ability to load Flash plugins on demand, modules for playing protected video content (DRM), an automatic update installation system, and the transmission of RLZ parameters during searches. Initially, Chrome 81 was planned to be released on March 17, but due to the SARS-CoV-2 coronavirus pandemic and the shift of developers to work from home, the release was The next release of Chrome 82 will be and the release of Chrome 83 is scheduled for May 19.
:
- The implementation of against loading mixed multimedia content (when resources are loaded via http:// on an HTTPS page) has continued. On pages opened via HTTPS, links to 'http://' will now be automatically replaced with 'https://' when loading images, scripts, iframes, audio, and video files, which was implemented in the previous release. If an image is not available via https, its loading is blocked (manually, you can mark the block through the menu available via the lock symbol in the address bar).
- support for the FTP protocol. In the next release, all FTP-related code from the codebase. It is recommended to use external FTP clients for FTP access. Temporarily, FTP support can be restored via the flag '--enable-ftp' or '--enable-features=FtpProtocol'.
- A tab grouping feature has been enabled for all users, allowing multiple similar-purpose tabs to be combined into visually separated groups. Each group can be assigned its own color and name. Previously, tab grouping was offered for testing only to a small percentage of users.
- In the API Support for augmented reality devices has been added. Web XR Hit Test display When saving a password in the built-in password manager, a warning is provided if the password is entered on an insecure site.
- in the Google Terms of Service (
- Changes have been made Google Terms of Serviceseparate section for Google Chrome and Chrome OS.
- Authentication using NTLM / Kerberos is disabled by default in incognito mode and guest sessions.
- TLS 1.3 implementation includes enhanced mechanisms to prevent downgrading to earlier versions of the TLS protocol. Previously, the protection against protocol version rollback was only partially implemented due to incompatibility with some improperly functioning proxy servers (Palo Alto Networks PAN-OS, Cisco Firepower Threat Defense, ASA with FirePOWER). Now, compatibility issues are a thing of the past, as most manufacturers of such proxies have released updates bringing their TLS implementations in line with specification requirements.
- An option "chrome://flags/#treat-unsafe-downloads-as-active-content" has been added to the settings, enabling warnings to be issued when attempting to download executable files from HTTPS site links (in Chrome 83, such warnings will be issued by default, while in Chrome 84 downloads will be blocked).
- Support for the Web NFC API has been added for mobile devices ). The Origin Trial allows the specified API to be used by applications downloaded from localhost or 127.0.0.1, or after registration and obtaining a special token, which is valid for a limited time for a specific site. In Origin Trial mode, the PointerLock API introduces the flag
- unadjustedMovement Badging
- Stabilized and now distributed outside of Origin Trials, the API The Media Session API has been extended
- Media Session API has been added. position tracking during composition playback. Data on playback speed, duration, and current playback time can be obtained, enabling the creation of custom interfaces for assessing position and traversing the track.
- The INTL API has implemented the method , through which localized names for languages, countries, currencies, date elements, etc., can be obtained.
- In the API , intended for collecting resource state data while the user is interacting with the web application, with the ability to use the 'buffered' flag with long-running tasks.
- By default, when displaying images, Chrome will consider orientation information from EXIF metadata. To explicitly override this behavior, the CSS property 'image-orientation' is proposed.
- A meta-tag and CSS property '' have been added, allowing the selection of a color scheme for rendering interface elements such as form buttons and scroll bars.
- The HTMLAnchorElement has been enhanced with the attribute , through which information can be passed about the need to translate the page into another language after clicking on the link.
- A new event type , which includes new properties to identify the element that triggered the form submission. For example, SubmitEvent allows the use of a single handler common to various buttons and links that lead to the form submission.
- in the web developer tools:
- In the context menu displayed for network requests, an item 'Copy > Copy as Node.js fetch' has been added to copy in the form of a fetch expression including Cookie data.
- A tooltip with an unescaped version of the data is provided when hovering over the CSS properties 'content'.
- The web console has improved error message detail for parsing fields in the source map.
- A setting 'Preferences > Sources > Allow scrolling past end of file' has been added to prevent scrolling beyond the end of the file when viewing the source text of the page.
- The Device panel has added the simulation of the smartphone screen Moto G4.
- The Cookies panel now highlights blocked Cookies with a yellow background.
- In the tables with Cookies displayed in the Network and Application panels, a column with data on the priority of Cookie selection has been added.
- All fields (except the size field) in the Cookie tables are now editable.
- support for TLS 1.0 and TLS 1.1 protocols before the release of Chrome 84. The inclusion of Chrome 83 has also been postponed. registration web forms that have been optimized for use on touch screens.
56 vulnerabilities. AddressSanitizer , , , and . No critical issues were found that allow bypassing all levels of browser protection and executing code in the system beyond the sandbox environment. As part of the bounty program for detecting vulnerabilities for the current release, Google has paid 23 awards totaling $26,000 (one award of $7,500, one award of $5,000, one award of $3,000, two awards of $2,000, three awards of $1,000, and eight awards of $500). The amount of 7 awards has yet to be determined.
Source: opennet.ru
