Release of web browser Chrome 136 with isolation of viewed links style

Google has released version 136 of the Chrome web browser. At the same time, a stable version of the free project Chromium, which forms the basis of Chrome, is available. Chrome differs from Chromium by the use of Google logos, a crash notification system, modules for playing copy-protected video content (DRM), automatic update installation, continuous Sandbox isolation, the inclusion of keys for the Google API, and the transmission of RLZ parameters during searches. For those who need more time to update, an Extended Stable branch is separately maintained, lasting 8 weeks. The next Chrome release, version 137, is scheduled for May 27.

Main changes in Chrome 136:

  • Added protection against information leakage regarding previously visited pages, which occurred due to the use of the CSS pseudo-class ':visited', allowing the styling of previously opened links. Up to version 136, clicking on a link would change its styling across all sites showing that link, regardless of which site initiated the click. On their own site, an attacker could determine if a user had previously visited links of interest by analyzing the styling change of those links. For example, if a list of links to different pages is created, previously visited pages in that list would be marked by the browser in a different color, allowing one to infer whether those links had been opened before.

    To block the leakage of information about visited links, Chrome has implemented isolation of the ':visited' selector processing based on the visited site, i.e., elements are now styled with ':visited' only if they were previously opened from the current site and in the context of the current iframe. This isolation is achieved through the hashing of the styles of visited links using a three-component key — the link, the top-level site, and the host used in the iframe.

    Release of web browser Chrome 136 with isolation of viewed links style

    For example, if a link from site "A" is clicked, that link will now only be highlighted on site "A" and will remain unchanged on the attacker's site. An exception is made only for iframes loaded from the main site (same-origin) and links to the current site. Thus, when opening site "A", links leading to site "A" will be highlighted even if transitions to them were from another site, but other links will only be highlighted if transitions were from site "A".

    Release of web browser Chrome 136 with isolation of viewed links style
    Release of web browser Chrome 136 with isolation of viewed links style

    In Firefox, protection against such leaks was introduced in 2010, but there were methods to bypass it. For instance, in 2024, Firefox 122 eliminated the possibility of analyzing pixel colors using filters that utilize the currentColor parameter and manipulations with the canvas tag in SVG.

  • The Android version implements the transmission of servers Google telemetry with data about APK packages downloaded through the browser. Currently, the functionality is limited to sending telemetry, but in the future, it will be used for issuing warnings and blocking the download of malicious APK files. The check is only performed when the enhanced protection mode is enabled in the browser settings (Safe Browsing > Enhanced protection).
  • For remote debugging, specifying a separate data directory is now required, which must be set at startup using the "—user-data-dir" parameter, which should be specified along with the "—remote-debugging-pipe" or "—remote-debugging-port" parameter. When using the default directory on Windows, Linux, and macOS, remote debugging will no longer work. The reason for the change is to counteract malware that utilizes remote debugging to extract data from Google Chrome. By using a separate directory, a different encryption key is applied that prevents access to the user's working data in the main directory. This change only applies to Chrome and is not enforced in Chromium.
  • The design of scrollbars has been improved on Linux and Windows platforms. When inactive, the scrollbar is hidden and appears only when scrolling resumes. For controlling the new scrollbar design, settings are provided at chrome://flags#fluent-overlay-scrollbars and chrome://flags#fluent-scrollbars.
    Release of web browser Chrome 136 with isolation of viewed links styleRelease of web browser Chrome 136 with isolation of viewed links style
  • In the CSS function attr(), the argument of type ‘string’ has been renamed to ‘raw-string’, in accordance with the decision of the working group coordinating the development of CSS specifications. This change aims to eliminate confusion due to the similarity of the expressions ‘attr(foo type())’ and ‘attr(foo string)’.
  • In the ProgressEvent API, used for creating progress indicators, the attributes ‘loaded’ and ‘total’ now utilize the type ‘double’ instead of ‘unsigned long long’, aligning with the behavior of the HTML element and allowing the indicator to reflect gradual changes of non-integer values, such as when changing a value from 0 to 1.
  • A static method ‘RegExp.escape’ has been proposed for escaping strings used within regular expressions. Strings escaped using RegExp.escape can be safely used as a pattern in the RegExp() constructor.
  • The website is allowed to automatically generate Passkey keys based on credentials that have already been saved for that site. The creation of Passkey occurs without displaying a separate modal dialog if the user has previously confirmed credential creation for the site.
  • A CSS property ‘dynamic-range-limit’ has been added to limit the maximum brightness of HDR content.
  • In the API Speculation Rules (), used for configuring resource preloading, the option to specify an optional ‘tag’ field for source tracking has been allowed. The content of this field will be sent via the HTTP header Sec-Speculation-Tags.
  • Support for the H265 (HEVC) codec has been added in WebRTC and the MediaRecorder API, in addition to previously supported VP8, H.264, VP9, and AV1.
  • The developer tools have enhanced the performance analysis panel capabilities. Reports on requests using the older HTTP/1.1 protocol, cache efficiency, and optimization using the font-display property have been added. The ‘Privacy and security > Privacy > Third-party cookies’ page now includes the ability to search for individual cookies. An experimental feature has been added to provide hints about issues with elements and attributes in the DOM.
    Release of web browser Chrome 136 with isolation of viewed links style

In addition to new features and bug fixes, the latest version addresses 8 vulnerabilities. Many of these vulnerabilities were identified through automated testing using tools like AddressSanitizer, MemorySanitizer, Control Flow Integrity, LibFuzzer, and AFL. No critical issues that would allow bypassing all browser security levels and executing code outside the sandbox environment were found. Under the bug bounty program for this release, Google awarded 4 rewards totaling $10,000 (one reward of $5,000, two rewards of $2,000, and one of $1,000).

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster