Chrome Release 150

Google has released version 150 of its Chrome web browser. A stable release of the open-source Chromium project, the foundation of Chrome, is also available. Chrome differs from Chromium in its use of Google logos, its crash notification system, modules for playing copy-protected video content (DRM), automatic update installation, always-on sandbox isolation, provisioning of Google API keys, and the use of RLZ parameters during search. For those who need more time to update, a separate Extended Stable branch is maintained for eight weeks. The next release, Chrome 151, is scheduled for July 28.

Key changes in Chrome 150 (1, 2, 3, 4):

  • The initial results of an initiative to update the interface design across various operating systems and remove unnecessary clutter are presented. New icons with smoother borders and animated effects for buttons, such as the main menu and page reload buttons, are included. The context menu structure has been simplified, eliminating rarely used or duplicated elements. A more modern design has been implemented for the configurator, download manager, and bookmark navigation page.
  • We've continued to develop the AI ​​mode, allowing interaction with the AI ​​agent from the address bar or from the page displayed when opening a new tab. The new version adds the ability to connect Chrome to the Gemini Spark AI agent for autonomously performing actions in the currently active tab while solving tasks that require interaction with web content (clicking buttons, following links, filling out forms, etc.). Additionally, contextual recommendations for using Gemini while working with the browser have been added. For example, when opening a long article, Chrome will offer to summarize the information using Gemini, and when editing text in a form, it will recommend checking or correcting the text using Gemini.
  • Some users use a single, simplified interface for linking to a Google account and syncing data, such as saved passwords and bookmarks. Syncing is integrated with account sign-in and is not presented as a separate option in settings. Users can connect Chrome to a Google account and use it to store passwords, bookmarks, browsing history, and tabs. Address autocomplete and autocomplete data are no longer synced across devices and are stored only locally.
  • Some users who have activated Enhanced Safe Browsing have the "HTTPS-First" feature enabled, which automatically redirects HTTP requests to HTTPS. To ensure compatibility with websites that don't support HTTPS, a fallback to HTTP is implemented if the HTTPS request fails after redirection or if certificate issues arise. A special warning is displayed when attempting to open a website over HTTP. In Chrome 154, this feature is planned to be enabled by default for all publicly accessible websites hosted on non-intranet networks, such as 192.168.0.1 and 10.0.0.0/8.
  • Support for the kExtensionManifestV2Disabled flag, which allowed the installation of extensions from the Chrome Web Store that use the second version of the Chrome manifest, has been removed. In the next release of Chrome 151, the AllowLegacyMV2Extensions setting, which allowed manual downloading of extensions based on the second version of the manifest in developer mode, will be removed. These flags allowed a workaround for installing the uBlock Origin extension.
  • Web Workers created using the "data:" URI (e.g. via "new Worker('data:text/javascript….')" are now isolated from the page they were created on and do not have access to local storage and cookies in the current context. domainThe change allows blocking the use of Web Workers that are not loaded from Server, but created on the fly via "data:", to access confidential data during XSS attacks.
  • Implemented protection against attacks that manipulate the maximum proxy connection limit to create a hidden communication channel between JavaScript code running in different tabs or to determine whether a specific website has been visited previously. For example, an attacker could occupy all available proxy connections, leaving only one socket unoccupied, and then analyze its availability when accessing a static resource. If the socket is unoccupied, the resource from the site being tested was served from the cache, meaning the user has previously downloaded it. The maximum connection limit for proxy TCP sockets now varies randomly.
  • Applying SVG filters to cross-origin or sandboxed iframes, as well as plugins (such as the built-in PDF viewer), is prohibited. This restriction helps protect against side-channel attacks, such as GPU.zip, and SVG Clickjacking attacks, which use SVG filters to overlay transparent content on other content to create an invisible button, such as a close button for an ad.
  • For standalone web applications (PWA, Progressive Web App), the ability to move to a new subdomain within a single base domain (for example, replacing drive.example.com with fileman.example.com) without user intervention is now available (previously, the PWA application was tied to the original domain, and in the event of a subdomain change, for example, during rebranding or restructuring, a manual reinstallation was required).
  • TLS includes support by default for the ML-DSA (CRYSTALS-Dilithium) digital signature generation algorithm, which is resistant to brute force on a quantum computer.
  • In version for Android Support for the FIDO Alliance Credential Exchange standard has been implemented, allowing you to import and export saved passwords and biometric identification settings using end-to-end client-side encryption, for example, for secure transfer between Google Password Manager and third-party password managers.
  • In version for Android The configurator offers a new unified interface for managing saved passwords and autofill data. The idea is to provide users with a single view of various classes of sensitive data stored by the browser, such as passwords, biometric authentication data, addresses, and passport information.
  • Added the "text-fit" CSS property to automatically scale the font size so that the text fits the width of the parent container (for example, when you need to fit a heading in a given area without wrapping the tail to another line or adapt the font to different screen resolutions).
  • The CSS property "background-clip" now supports the "border-area" parameter, which simplifies the creation of gradient borders by drawing the element's background strictly within the area occupied by the border.
  • Added CSS function image(), which allows you to generate an image filled with a specified color.
  • Origin trials have begun testing the EVP (email verification protocol) for automatic cryptographic confirmation of email ownership without the need to send one-time verification codes to email.
  • The focusgroup HTML attribute has been added for declarative control of keyboard focus switching within composite components, such as menus, without using JavaScript. For example, after tabbing out of a group of elements and back in, the browser will return focus to the last active element, not the first element in the list.
  • Improvements have been made to web developer tools. Features have been added for inspecting and debugging WebMCP tools used to integrate websites with AI agents using the MCP protocol. In-place editing of "@container," "@counter-style," and "@function" rules is now possible in the style panel.

In addition to new features and bug fixes, the new version addresses 433 vulnerabilities. Many of these vulnerabilities were identified through automated testing using AddressSanitizer, MemorySanitizer, Control Flow Integrity, LibFuzzer, and AFL. Twenty issues were assigned a critical severity level, meaning they could bypass all browser protection layers and execute code outside the sandbox environment. Fourteen critical issues were caused by use-after-free access, three by insufficient validation of untrusted input, two by buffer overflows, and one by type confusion. As part of the vulnerability bounty program for the current release, Google has paid out $319,000 (one $250,000 bounty (CVE-2026-14382 in the ANGLE library), three bounties of $10000, $2500, $2000, and $1000, two bounties of $3000, and one bounty each of $8000, $5000, and $4000).

Source: opennet.ru

Buy reliable hosting for sites with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster