Everything new in Chrome 104
Latest update from Google, Chrome 104 is here.Assuming you have Surprisingly generous system requirementsyou can update your browser now to take advantage of it New features and changes. The biggest UI change is for Chromebook users running Chrome OS, All Chrome users benefit from security patches.
For new Chrome updates 27 security patches
The most important reason to update Google Chrome is to install the 27 security patches that come with it. To be clear, the security situation is not dire. According to Google’s Chrome Releases blogNone of the 27 vulnerabilities patched in Chrome 104 are “zero days.” In other words, there is no evidence that these vulnerabilities were actually exploited by malicious users. If you’re currently running Chrome 103, your chances of being targeted by one of these security flaws are slim to none. That said, these 27 vulnerabilities are now publicly known, so it’s only a matter of time before bad actors discover how to use them against users who don’t have Chrome 104.
In addition, seven of these flaws were rated “High”, meaning they are more threatening than others. Below is the full list, with “high” vulnerabilities listed at the top.
- [$15000][1325699] high CVE-2022-2603: Used after free in Omnibox. Report anonymously on 2022-05-16
- [$10000][1335316] high CVE-2022-2604: Used after release in Safe Browsing. Reported by Nan Wang (@eternalssakura13) of 360 Alpha Lab and his Guang Gong on 2022-06-10.
- [$7000][1338470] high CVE-2022-2605: Out-of-bounds read in Dawn. Reported by Looben Yang on Jun 22, 2022
- [$5000][1330489] high CVE-2022-2606: Used after release in managed device APIs. Reported by Nan Wang (@eternalssakura13) and Guang Gong of 360 Alpha Lab on 2022-05-31.
- [$3000][1286203] high CVE-2022-2607: Using after free in Tab Strip. Reported by @ginggilBesel on 2022-01-11
- [$3000][1330775] high CVE-2022-2608: Use after free in summary mode. Reported by Khalil Zhani on June 1, 2022
- [$TBD][1338560] high CVE-2022-2609: Used after Free in Nearby Share. Reported by koocola (@alo_cook) and his Guang Gong at his 360 Vulnerability Lab on 2022-06-22.
- [$8000][1278255] Medium CVE-2022-2610: Insufficient policy enforcement in background fetch. Reported by Maurice Dauer on Dec 9, 2021
- [$5000][1320538] Medium CVE-2022-2611: Improper implementation of fullscreen API. Reported on 28 Apr 2022 by Irvan Kurniawan (sourc7)
- [$5000][1321350] Medium CVE-2022-2612: Side-channel information disclosure in keyboard input. Reported by Erik Kraft (erik.kraft5@gmx.at), Martin Schwarzl (martin.schwarzl@iaik.tugraz.at) on 2022-04-30.
- [$5000][1325256] Medium CVE-2022-2613: Use after freeing on input. Reported by Piotr Tworek (Vewd) on May 13, 2022.
- [$5000][1341907] Medium CVE-2022-2614: Use after free in sign-in flow. Reported by raven at KunLun lab on 2022-07-05
- [$4000][1268580] Medium CVE-2022-2615: Poor policy enforcement on cookies. Reported by Maurice Dauer on 10 November 2021
- [$3000][1302159] Medium CVE-2022-2616: Improper implementation of extension API. Reported by Alesandro Ortiz on Mar 2, 2022
- [$2000][1292451] Medium CVE-2022-2617: Use after free in extension API. Reported by @ginggilBesel on 2022-01-31
- [$2000][1308422] Medium CVE-2022-2618: Insufficient internal untrusted input validation. Reported by asnine on 2022-03-21
- [$2000][1332881] Medium CVE-2022-2619: Insufficient validation of untrusted input in settings. Reported by Oliver Dunk on June 4, 2022
- [$2000][1337304] Medium CVE-2022-2620: Use after free in WebUI. Reported by Nan Wang (@eternalssakura13) and Guang Gong of 360 Alpha Lab on 2022-06-17.
- [$1000][1323449] Medium CVE-2022-2621: Use after free in extension. Reported by Huyna at Viettel Cyber Security on May 7, 2022
- [$1000][1332392] Medium CVE-2022-2622: Inadequate validation of untrusted input in Safe Browsing. Reported by Imre Rad (@ImreRad) and @j00sean on 2022-06-03
- [$1000][1337798] Medium CVE-2022-2623: Use after releasing offline. Reported by raven at KunLun lab on 2022-06-20
- [$TBD][1339745] Medium CVE-2022-2624: PDF heap buffer overflow. Reported by YU-CHANG CHEN and CHIH-YEN CHANG working in DEVCORE Internship Program on June 27, 2022
G/O Media can earn commissions
70% off
Jachs NY Summer Shorts Sale
SUMMER STYLE EXCLUSIVE SALE
Available in patterns, solid colors, twill, chinos, and 7-9 inch inseam, these classic shorts tell stories.
But security updates aren’t everything. According to HowTo GeekHere’s what else you can expect after upgrading to Chrome 104 (bonus points if you have a Chromebook):
Chrome OS officially supports light and dark modes
Dark Mode is the best in any software This was a requested feature and is now available on Chrome OS. With the latest update, Google not only officially supports switching between light and dark modes, but now you can switch between them automatically. I use this feature on my device so when the sun starts to set everything goes into dark mode.
Chrome OS new start menu
aAnother cool feature: Chromebooks now have a Windows-like start menu called “Productivity Launcher”. It comes with a Google search bar and Assistant shortcuts. In addition, a new feature displays the date on the other side of the system tray.: Click to see a large and handy calendar widget.
Share only a selected part of your screen in a video recording
Anyone who shares their screen regularly will welcome this update: Web app developers can implement a feature called region capture, which allowed users to snip an area of the display to record or share instead of focusing on an entire window or entire screen. This feature helps ease fears of being overly shared and allows you to control exactly what parts of your screen others can see.
Of course, it’s up to developers to implement region capture in their services, so you may not see this feature right away.Met’But I have Chrome 104.
LazyEmbeds (limited testing)
Google is also testing a feature called LazyEmbeds. This feature only loads when the content embedded in the website is displayed on the screen. This is a spin-off of “lazy loading” where the browser only loads the site’s content when the user looks at it, instead of loading the entire site and its content at once. At this time, only 1% of Chrome users participate in this test, so it won’t be fully rolled out with version 104.
New developer update
With each new version of Chrome, Google rolls out new features for developers. The full list of changes is Google’s DevTools blog and the chrome blogeven as This DevTools 104 video:
How to update Google chromium
good luck, updating Chrome on your computer is easy. Click the three dots in the upper right corner of the window to Help > About Google ChromeAllow Chrome to load for a while—wWhen you are ready to update[再起動]Click to restart your browser in Chrome 104.
Everything new in Chrome 104
Source link Everything new in Chrome 104