Ukukhishwa kwe-Chrome 103

I-Google yembule ukukhishwa kwesiphequluli sewebhu se-Chrome 103. Ngesikhathi esifanayo, ukukhululwa okuzinzile kwephrojekthi yamahhala ye-Chromium, esebenza njengesisekelo se-Chrome, kuyatholakala. Isiphequluli se-Chrome siyahluka kusukela ku-Chromium ekusebenziseni amalogo e-Google, ukuba khona kwesistimu yokuthumela izaziso uma kuba nokuphahlazeka, amamojula okudlala okuqukethwe kwevidiyo okuvikelwe ikhophi (i-DRM), isistimu yokufaka ngokuzenzakalela izibuyekezo, evumela unaphakade ukuhlukaniswa kwe-Sandbox , ihlinzeka ngokhiye ku-Google API futhi idlulisela i-RLZ- uma isesha. Kulabo abadinga isikhathi esengeziwe sokubuyekeza, igatsha Le-Extended Stable lisekelwa ngokuhlukile, lilandelwa amaviki angu-8. Ukukhishwa okulandelayo kwe-Chrome 104 kuhlelelwe u-Agasti 2.

Izinguquko ezibalulekile ku-Chrome 103:

  • Kwengezwe umhleli wesithombe esivivinywayo esibizelwe ukuhlela izithombe-skrini zekhasi. Umhleli uhlinzeka ngemisebenzi efana nokunqampuna, ukukhetha indawo, ukudweba ngebhulashi, ukukhetha umbala, ukungeza amalebula ombhalo, nokubonisa izimo ezivamile nezinto zokuqala ezifana nemigqa, onxande, imibuthano, nemicibisholo. Ukuze unike amandla umhleli, kufanele wenze kusebenze izilungiselelo β€œchrome://flags/#sharing-desktop-screenshots” kanye β€œne-chrome://flags/#sharing-desktop-screenshots-edit”. Ngemva kokudala isithombe-skrini ngemenyu yokwabelana kubha yekheli, ungaya kusihleli ngokuchofoza inkinobho ethi "Hlela" ekhasini lokubuka kuqala lesithombe-skrini.
    Ukukhishwa kwe-Chrome 103
  • Amandla omshini owengezwe ku-Chrome 101 okunikezela kusengaphambili okuqukethwe kwezincomo kubha yekheli le-Omnibox anwetshiwe. Ukunikezwa okubikezelayo kuhambisana nekhono elikhona ngaphambili lokulayisha izincomo okungenzeka zizulazulwe ngaphandle kokulinda ukuchofoza komsebenzisi. Ngaphezu kokulayisha, okuqukethwe kwamakhasi ahlobene nezincomo manje kunganikezwa kubhafa (okuhlanganisa ukusebenza kombhalo kanye nesihlahla se-DOM formation), okuvumela ukuboniswa okusheshayo kwezincomo ngemva kokuchofoza . Ukuze ulawule ukunikezwa okubikezelwayo, izilungiselelo β€œchrome://flags/#enable-prerender2”, β€œchrome://flags/#omnibox-trigger-for-prerender2” kanye β€œchrome://flags/#search-suggestion-for -” ziyaphakanyiswa. prerender2".

    I-Chrome 103 ye-Android yengeza i-Speculations Rules API, evumela ababhali bewebhusayithi ukuthi batshele isiphequluli ukuthi yimaphi amakhasi umsebenzisi okungenzeka awavakashele. Isiphequluli sisebenzisa lolu lwazi ukuze silayishe ngokuqhubekayo futhi sinikeze okuqukethwe kwekhasi.

  • Inguqulo ye-Android ifaka isiphathi sephasiwedi esisha esinikezela ngomuzwa ofanayo wokuphathwa kwephasiwedi otholakala ezinhlelweni zokusebenza ze-Android.
  • Inguqulo ye-Android yengeze usekelo lwesevisi "Nge-Google", evumela umsebenzisi ukuthi abonise ukubonga kumasayithi ayintandokazi akhe abhalise nesevisi ngokudlulisa izitika zedijithali ezikhokhelwayo noma zamahhala. Isevisi okwamanje itholakala kuphela kubasebenzisi base-US.
    Ukukhishwa kwe-Chrome 103
  • Ukugcwaliswa okuzenzakalelayo kwezinkambu okuthuthukisiwe ngezinombolo zekhadi lokukhokha lesikweletu neledebhithi, manje esisekela amakhadi alondolozwe nge-Google Pay.
  • Inguqulo ye-Windows isebenzisa iklayenti le-DNS elakhelwe ngaphakathi ngokuzenzakalelayo, elibuye lisetshenziswe ezinguqulweni ze-macOS, Android ne-Chrome OS.
  • I-Local Font Access API isizinzisiwe futhi yanikezwa wonke umuntu, ongachaza futhi usebenzise amafonti afakwe ohlelweni, futhi ulawule amafonti ezingeni eliphansi (isibonelo, ukuhlunga nokuguqula ama-glyphs).
  • Ukwesekwa okwengeziwe kwekhodi yempendulo ye-HTTP engu-103, ekuvumela ukuthi wazise iklayenti mayelana nokuqukethwe kwezinye izihloko ze-HTTP ngokushesha ngemva kwesicelo, ngaphandle kokulinda iseva ukuthi iqedele yonke imisebenzi ehlobene nesicelo futhi iqale ukukhonza okuqukethwe. Ngendlela efanayo, unganikeza izeluleko mayelana nezinto ezihlobene nekhasi elinikezwayo ezingalayishwa ngaphambili (isibonelo, izixhumanisi ze-css ne-javascript ezisetshenziswa ekhasini zinganikezwa). Ngemva kokuthola ulwazi mayelana nezinsiza ezinjalo, isiphequluli singaqala ukuzilanda ngaphandle kokulinda ikhasi eliyinhloko ukuthi liqedele ukunikeza, okunciphisa sonke isikhathi sokucubungula isicelo.
  • Kumodi Yezilingo Zomsuka (izici zokuhlola ezidinga ukwenziwa kusebenze okuhlukene), ukuhlolwa kwe-Federated Credential Management (FedCM) API kuze kube manje kuqale emihlanganweni yeplathifomu ye-Android kuphela, ekuvumela ukuthi udale izinsizakalo zomazisi ezihlanganisiwe eziqinisekisa ubumfihlo kanye nomsebenzi ngaphandle kwesiphambano. -izindlela zokulandelela isayithi, njengokucutshungulwa kwe-cookie yenkampani yangaphandle . I-Origin Trial isho amandla okusebenza ne-API eshiwo ezinhlelweni ezilandwe ku-localhost noma 127.0.0.1, noma ngemva kokubhalisa nokwamukela ithokheni elikhethekile elisebenza isikhathi esilinganiselwe sesayithi elithile.
  • I-Client Hints API, eyathuthukiswayo njengokungena esikhundleni sesihloko somenzeli womsebenzisi futhi ikuvumela ukuthi unikeze ngokukhetha idatha mayelana nemingcele ethile yesiphequluli nesistimu (inguqulo, inkundla, njll.) kuphela ngemuva kwesicelo seseva, yengeze ikhono lokushintsha amagama angelona iqiniso ohlwini lwezihlonzi zesiphequluli, ngokuya ngezifaniso ne-GREASE (Yenza Izandiso Ezingahleliwe Futhi Uqinise Izandiso) esetshenziswa ku-TLS. Ngokwesibonelo, ngaphezu '"Chrome"; v="103β€³' kanye ne-'"Chromium"; v=Β»103β€³' isihlonzi esingahleliwe sesiphequluli esingekho ''(Cha; Isiphequluli"; v=Β»12β€³' singangezwa ohlwini. Ukushintsha okunjalo kuzosiza ekuboneni izinkinga ngokucubungula izihlonzi zeziphequluli ezingaziwa, okuholela eqinisweni lokuthi ezinye iziphequluli ziphoqeleka ukuba zizenze ezinye iziphequluli ezidumile ukuze zidlule ukuhlola ngokumelene nohlu lweziphequluli ezamukelekayo.
  • Amafayela akufomethi yesithombe se-AVIF engeziwe ohlwini lokwabelana okuvunyelwe nge-iWeb Share API.
  • Ukwesekwa okwengeziwe kwefomethi yokuminyanisa "deflate-raw", okuvumela ukufinyelela emfudlaneni ominyanisiwe ongenalutho ngaphandle kwezihloko namabhulokhi wokugcina wesevisi, angasetshenziswa, isibonelo, ukufunda nokubhala amafayela e-zip.
  • Ezicini zefomu lewebhu, kungenzeka ukusebenzisa isibaluli se-"rel", esikuvumela ukuthi usebenzise ipharamitha ye-"rel=noreferrer" ekuzulazuleni kumafomu ewebhu ukuze ukhubaze ukudluliswa kwesihloko se-Referer noma i-"rel=noopener" ukuze ukhubaze isilungiselelo. isakhiwo se-Window.opener futhi sinqabele ukufinyelela kumongo lapho inguquko yenziwe khona.
  • Ukuqaliswa komcimbi we-popstate kuhambisane nokuziphatha kweFirefox. Umcimbi we-popstate manje uxoshwa ngokushesha ngemva kokushintshwa kwe-URL, ngaphandle kokulinda umcimbi wokulayisha ukuthi wenzeke.
  • Emakhasini avulwe ngaphandle kwe-HTTPS futhi kusukela kumabhulokhi e-iframe, ukufinyelela ku-Gampepad API kanye ne-API Yesimo Sebhethri akuvunyelwe.
  • Indlela yokukhohlwa() yengezwe entweni ye-SerialPort ukuze kuhoxiswe izimvume ezinikezwe umsebenzisi ngaphambilini ukuze afinyelele imbobo ye-serial.
  • Isibaluli sebhokisi elibonakalayo sengeziwe esakhiweni se-CSS se-overflow-clip-margin, esinquma ukuthi ungaqala kuphi ukusika okuqukethwe okweqa umngcele wendawo (kungathatha amanani ibhokisi lokuqukethwe, ibhokisi lokunamathisela kanye nomngcele- ibhokisi).
  • Kumabhulokhi e-iframe anesibaluli se-sandbox, ukubiza amaphrothokholi angaphandle nokuvula izinhlelo zokusebenza zesibambi sangaphandle akuvunyelwe. Ukuze ukhiphe umkhawulo, sebenzisa izigelekeqe ezivumelayo, vumela-phezulu-ukuzulazula, kanye nokuvumela ukuzulazula okuphezulu-ngokusebenzisa-umsebenzisi izici zokwenza kusebenze.
  • I-elementi ayisasekelwa , okwaba yize ngemva kokuthi ama-plugin engasasekelwa.
  • Ukuthuthukiswa kwenziwe kumathuluzi onjiniyela bewebhu. Isibonelo, kuphaneli Yezitayela kube nokwenzeka ukunquma umbala wephoyinti ngaphandle kwewindi lesiphequluli. Ukubuka kuqala okuthuthukisiwe kwamanani epharamitha kusilungisi sephutha. Kwengezwe ikhono lokushintsha ukuhleleka kwamaphaneli kusixhumi esibonakalayo se-Elements.

Ngokungeziwe ezenzweni ezintsha nokulungiswa kweziphazamisi, inguqulo entsha isusa ubungozi obuyi-14. Ubungozi obuningi buhlonzwe njengomphumela wokuhlolwa okuzenzakalelayo kusetshenziswa i-AddressSanitizer, MemorySanitizer, Control Flow Integrity, LibFuzzer kanye namathuluzi e-AFL. Enye yezinkinga (i-CVE-2022-2156) inikezwe izinga elibucayi lengozi, elisikisela ikhono lokudlula wonke amazinga okuvikela isiphequluli kanye nokukhipha ikhodi kusistimu engaphandle kwendawo ye-sandbox. Imininingwane mayelana nalokhu kuba sengozini ayikadalulwa, kwaziwa kuphela ukuthi kubangelwa ukufinyelela ibhulokhi yememori ekhululiwe (ukusebenzisa ngemva kwamahhala).

Njengengxenye yohlelo lokukhokha imiklomelo yemali ngokuthola ubungozi ekukhishweni kwamanje, i-Google ikhokhele imiklomelo engu-9 enani lamadola ayizinkulungwane ezingu-44 (umklomelo owodwa wama-$20000, umklomelo owodwa wama-$7500, umklomelo owodwa ka-$7000, imiklomelo emibili engu-$3000 kanye eyodwa $2000, $1000 kanye $500). ). Usayizi womvuzo wokuba sengcupheni okubalulekile awukakanqunywa.

Source: opennet.ru

Engeza amazwana