Ukukhutshwa kweChrome 103

I-Google ityhile ukukhululwa kwesiphequluli sewebhu se-Chrome 103. Ngexesha elifanayo, ukukhululwa okuzinzile kweprojekthi yeChromium yamahhala, esebenza njengesiseko seChrome, iyafumaneka. Isikhangeli seChrome sihluke kwiChromium ekusebenziseni iilogo zeGoogle, ubukho benkqubo yokuthumela izaziso kwimeko yokuphazamiseka, iimodyuli zokudlala umxholo wevidiyo okhuselweyo okhuselweyo (DRM), inkqubo yokufaka uhlaziyo ngokuzenzekelayo, ukuvumela ngokusisigxina ukwahlukaniswa kweSandbox. , inikezela ngezitshixo kwiGoogle API kunye nokuthumela iRLZ- xa uziphendla. Kwabo bafuna ixesha elingakumbi lokuhlaziya, i-Extended Stable branch ixhaswa ngokwahlukeneyo, ilandelwa ziiveki ezisi-8. Ukukhutshwa okulandelayo kweChrome 104 kucwangciselwe i-2 ka-Agasti.

Utshintsho oluphambili kwiChrome 103:

  • Kongezwe umhleli womfanekiso wovavanyo obizelwe ukuhlela iifoto zesikrini. Umhleli ubonelela ngemisebenzi efana nokunqampuna, ukukhetha indawo, ukupeyinta ngebrashi, ukukhetha umbala, ukongeza iileyibhile zeteksti, kunye nokubonisa iimilo eziqhelekileyo kunye neeprimitive ezifana nemigca, uxande, izangqa, kunye neentolo. Ukwenza umhleli asebenze, kufuneka uvule useto "chrome://flags/#sharing-desktop-screenshots" kunye "chrome://flags/#sharing-desktop-screenshots-edit". Emva kokwenza umfanekiso weskrini ngemenyu yoKwabelana kwibha yedilesi, ungaya kumhleli ngokucofa iqhosha elithi "Hlela" kwiphepha le-screenshot preview.
    Ukukhutshwa kweChrome 103
  • Ubunakho besixhobo esongeziweyo kwi-Chrome 101 ukulungiselela kwangaphambili umxholo weengcebiso kwibha yedilesi ye-Omnibox zandisiwe. Unikezelo olusebenzayo luncedisana nesakhono ebesikhona ngaphambili sokulayisha izindululo ekunokwenzeka ukuba zihambe ngaphandle kokulinda umsebenzisi ukuba acofe.Ukongeza ekulayisheni, umxholo wamaphepha anxulumene nezindululo ngoku unokunikezelwa kwisithinteli (kubandakanya ukwenziwa kweskripthi kunye neDOM. ukubunjwa komthi), okuvumela ukuboniswa ngoko nangoko kweengcebiso emva konqakrazo . Ukulawula unikezelo oluqikelelwayo, izicwangciso β€œchrome://flags/#enable-prerender2”, β€œchrome://flags/#omnibox-trigger-for-prerender2” kunye β€œchrome://flags/#search-suggestion-for -” ziyacetyiswa. prerender2".

    I-Chrome 103 ye-Android yongeza i-API yeMithetho yoQingqo, evumela ababhali bewebhusayithi ukuba baxelele umkhangeli ukuba ngawaphi amaphepha anokuthi andwendwelwe ngumsebenzisi. Isikhangeli sisebenzisa olu lwazi ukulayisha ngokuqhubekayo kunye nokunikezela umxholo wephepha.

  • Inguqulelo ye-Android inomphathi omtsha wegama lokugqitha obonelela ngamava olawulo adityanisiweyo afanayo afumaneka kwii-apps ze-Android.
  • Inguqulo ye-Android yongeze inkxaso yenkonzo "NgeGoogle", evumela umsebenzisi ukuba abonise ukubonga kwiindawo zabo ezizithandayo ezibhalise ngenkonzo ngokudlulisela izitikha zedijithali ezihlawulelwayo okanye zamahhala. Le nkonzo okwangoku ifumaneka kuphela kubasebenzisi base-US.
    Ukukhutshwa kweChrome 103
  • Ukuzaliswa ngokuzenzekelayo kweendawo ngeenombolo zekhadi lokuthenga ngetyala kunye nekhadi lokubhatalwa, ngoku lixhasa amakhadi agcinwe nge-Google Pay.
  • Inguqulelo yeWindows isebenzisa iklayenti ye-DNS eyakhelwe-ngaphakathi ngokungagqibekanga, ekwasetyenziswa yinguqulelo yeMacOS, Android kunye neChrome OS.
  • I-API yoFikelelo lwefonti yaseKhaya izinzile kwaye yanikezelwa kuye wonke umntu, onokuthi ngayo uchaze kwaye usebenzise iifonti ezifakwe kwisistim, kunye nokukhohlisa iifonti kwinqanaba elisezantsi (umzekelo, isihluzo kunye nokuguqula iiglyphs).
  • Inkxaso eyongeziweyo yekhowudi yempendulo ye-HTTP ye-103, evumela ukuba uxelele umxhasi malunga neziqulatho zezinye iintloko ze-HTTP ngokukhawuleza emva kwesicelo, ngaphandle kokulinda umncedisi ukugqiba yonke imisebenzi ehambelana nesicelo kwaye uqale ukukhonza umxholo. Ngendlela efanayo, unganikezela ngeengcebiso malunga nezinto eziyelelene nephepha elihanjiswayo ezinokulayishwa kwangaphambili (umzekelo, amakhonkco kwi css kunye nejavascript esetyenziswa kwiphepha inokunikezelwa). Emva kokuba ifumene ulwazi malunga nezixhobo ezinjalo, isikhangeli sinokuqalisa ukuzikhuphela ngaphandle kokulinda iphepha eliphambili ukuba ligqibe unikezelo, nto leyo ecutha lonke ixesha lokwenziwa kwesicelo.
  • Kwimowudi yovavanyo lwemvelaphi (iimpawu zovavanyo ezifuna ukusebenza ngokwahlukileyo), uvavanyo lwe-Federated Credential Management (FedCM) API sele iqalile kuphela kwiindibano zeqonga le-Android, elikuvumela ukuba wenze iinkonzo zesazisi ezidibeneyo eziqinisekisa ubumfihlo kunye nomsebenzi ngaphandle komnqamlezo. -iindlela zokulandelela indawo, ezifana nokusetyenzwa kweCookie yomntu wesithathu. Uvavanyo lwemvelaphi luthetha ukukwazi ukusebenza kunye ne-API echaziweyo kwizicelo ezikhutshelwe kwi-localhost okanye i-127.0.0.1, okanye emva kokubhalisa kunye nokufumana ithokheni ekhethekileyo esebenzayo ixesha elilinganiselweyo kwindawo ethile.
  • I-API yeeNgcebiso zabathengi, ephuhliswayo njengokutshintshwa kwesihloko soMsebenzisi-Agent kwaye ikuvumela ukuba unikeze ngokukhetha idatha malunga nesikhangeli esithile kunye neeparamitha zenkqubo (uguqulelo, iqonga, njl.njl.) kuphela emva kwesicelo somncedisi, wongeze i ukukwazi ukufaka amagama angeyonyani endaweni yamagama obuxoki kuluhlu lwezichongi zebrawuza, ngokuhambelana ne-GREASE (Yenza Izandiso eziNgaQongayo kunye noKugcina Ukwandiswa) indlela esetyenziswa kwi-TLS. Umzekelo, ukongeza kwi "Chrome"; v = "103"' kunye ne'"Chromium"; v=Β»103β€³' isichongi esingacwangciswanga somkhangeli zincwadi ongekhoyo ''(Ayikho; Isikhangeli"; v=Β»12β€³' singongezwa kuluhlu. Utshintsho olunjalo luya kunceda ukuchonga iingxaki ngokuchongwa kwemisebenzi yezikhangeli ezingaziwayo, nto leyo ekhokelela kwinto yokuba ezinye izikhangeli zinyanzelwa ukuba zizenze ezinye iibhrawuza ezidumileyo ukuba zidlule ukukhangela ngokuchasene noluhlu lwabakhangeli abamkelekileyo.
  • Iifayile kwifomathi yomfanekiso we-AVIF zongezwe kuluhlu lokwabelana okuvunyelweyo nge-iWeb Share API.
  • Inkxaso eyongeziweyo yefomathi yokucinezela "deflate-raw", evumela ukufikelela kumjelo oxinyiweyo ongenanto ngaphandle kweentloko kunye neebhloko zokugqibela zenkonzo, ezinokusetyenziswa, umzekelo, ukufunda nokubhala iifayile ze-zip.
  • Kwiziqalelo zefomu yewebhu, kuyenzeka ukusebenzisa uphawu lwe "rel", olukuvumela ukuba usebenzise i "rel=noreferrer" iparamitha ukukhangela kwiifomu zewebhu ukuvala ugqithiso lwesihloko soMbhekiseli okanye "rel=noopener" ukuvala useto. ipropati ye-Window.opener kwaye ukwala ukufikelela kumxholo apho utshintsho lwenziwe khona.
  • Ukuphunyezwa komcimbi we-popstate ulungelelaniswe nokuziphatha kweFirefox. Isiganeko se-popstate ngoku sigxothwe ngokukhawuleza emva kokutshintsha kwe-URL, ngaphandle kokulinda ukuba umcimbi womthwalo wenzeke.
  • Kumaphepha avulwe ngaphandle kweHTTPS kunye neebhloko ze-iframe, ukufikelela kwiGampepad API kunye neBattery Status API akuvumelekanga.
  • Indlela yokulibala () yongezwe kwinto yeSeriPort ukuncama iimvumelwano ebezinikwe ngaphambili kumsebenzisi ukufikelela kwizibuko lothotho.
  • Uphawu lwebhokisi ebonwayo yongezwe kwipropathi yeCSS, emisela ukuba ungaqala phi ukucheba umxholo ogqithela ngaphaya komda wendawo (inokuthatha amaxabiso-ibhokisi yomxholo, ibhokisi yepadding kunye nomda- ibhokisi).
  • Kwiibhloko ze-iframe ezinophawu lwebhokisi yesanti, ukubiza iiprothokholi zangaphandle kunye nokuqaliswa kwezicelo zokuphatha zangaphandle akuvumelekanga. Ukukhuphela ngaphezulu uthintelo, sebenzisa ii-vumela-popups, vumela-phezulu-ukhangelo, kwaye vumela-phezulu-ukukhangela-nomsebenzisi-activation properties.
  • Into ayisaxhaswa , eyaba yintsingiselo emva kokuba iiplagi zingasaxhaswanga.
  • Uphuculo lwenziwe kwizixhobo zabaphuhlisi bewebhu. Umzekelo, kwiphaneli yeZimbo kuye kwenzeka ukumisela umbala wendawo ngaphandle kwefestile yomkhangeli zincwadi. Ukuphuculwa komboniso wamaxabiso eparameter kwidebugger. Kongezwe amandla okutshintsha ulandelelwano lweephaneli kwi-Elements interface.

Ukongeza kwizinto ezintsha kunye nokulungiswa kwe-bug, inguqulelo entsha isusa ubuthathaka obuli-14. Uninzi lobuthathaka luchongiwe ngenxa yovavanyo oluzenzekelayo kusetyenziswa idilesi yeSanitizer, MemorySanitizer, Control Flow Integrity, LibFuzzer kunye nezixhobo zeAFL. Enye yeengxaki (i-CVE-2022-2156) inikwe inqanaba elibalulekileyo lengozi, elithetha ukukwazi ukudlula onke amanqanaba okukhusela isiphequluli kunye nokwenza ikhowudi kwinkqubo ngaphandle kwendawo yebhokisi yesanti. Iinkcukacha ngobu sesichengeni azikachazwa, kwaziwa kuphela ukuba kubangelwa kukufikelela kwibhloko yenkumbulo ekhululweyo (ukusetyenziswa-emva kokukhululeka).

Njengenxalenye yenkqubo yokuhlawula imbuyekezo yemali ngokufumanisa ubuthathaka ngokukhutshwa kwangoku, uGoogle uhlawule amabhaso ayi-9 kwisixa-mali sama-44 amawaka eedola zase-US (ibhaso elinye le-20000 yeedola, ibhaso elinye le-7500 yeedola, ibhaso elinye le-7000 yeedola, amabhaso amabini e-3000 yeedola kunye enye i-$2000, i-$1000 ne-$500). ). Ubungakanani bomvuzo wobuthathaka obubalulekileyo abukamiselwa.

umthombo: opennet.ru

Yongeza izimvo