Chrome does not work with all CSS minifiers such as whitespace around a media query's `and` keyword. (333035)
Security Fixes and Rewards
This update includes 14 security fixes. Below, we highlight fixes that were either contributed by external researchers or particularly interesting. Please see the Chromium security page for more information.
[$1000][330420] High CVE-2013-6649: Use-after-free in SVG images. Credit to Atte Kettunen of OUSPG.
[$3000][331444] High CVE-2013-6650: Memory corruption in V8. This issue was fixed in v8 version 3.22.24.16. Credit to Christian Holler.
We would also like to thank cloudfuzzer and miaubiz for working with us during the development cycle to prevent security bugs from ever reaching the stable channel. $6000 in additional rewards were issued.
A partial list of changes is available in the SVN log. Interested in switching release channels? Find out how. If you find a new issue, please let us know by filing a bug.
We highlight fixes contributed by external researchers or particularly interesting. Please see the Chromium security page for more information.
[$5000][321940] High CVE-2013-6643: Unprompted sync with an attacker’s Google account. Credit to Joao Lucas Melo Brasio.
If you find new issues, please let us know by visiting our forum or filing a bug. Interested in switching channels? Find out how. You can submit feedback using ‘Report an issue...’ in the Chrome menu (3 horizontal bars in the upper right corner of the browser).
This update includes 11 security fixes. Below, we highlight fixes that were either contributed by external researchers or particularly interesting. Please see the Chromium security page for more information.
[$1000][249502] High CVE-2013-6646: Use-after-free in web workers. Credit to Collin Payne.
[$1000][326854] High CVE-2013-6641: Use-after-free related to forms. Credit to Atte Kettunen of OUSPG.
[$1000][324969]High CVE-2013-6642: Address bar spoofing in Chrome for Android. Credit to lpilorz.
[$5000][321940] High CVE-2013-6643: Unprompted sync with an attacker’s Google account. Credit to Joao Lucas Melo Brasio.
[318791] Medium CVE-2013-6645 Use-after-free related to speech input elements. Credit to Khalil Zhani.
As usual, our ongoing internal security work responsible for a wide range of fixes:
[333036] CVE-2013-6644: Various fixes from internal audits, fuzzing and other initiatives.
Keyboard input is not working correctly in Windows 8 metro mode. This may impact IMEs, RTL layouts. (164964)
Trackpad users may not be able to scroll horizontally. (332797)
Drag and drop files into Chrome may not work properly. (332579)
Closing Tab by pressing the ‘x’ button may not work. (332334)
On some machines the browser UI can flicker when resizing the window. (305432)
Opening another profile using the profile icon switcher in Win8 mode results in the new window being opened on the Desktop instead of in Win8 mode. (325919)
Chrome conflicts with Norton Software including Identity Safe Toolbar. (327110)
Windows 8 mode is not yet supported on HiDPI devices and Windows 8 mode is not supported on machines without hardware acceleration (160457 and 332503).
Using Nvidia's Stereoscopic 3D feature turns Chrome pink. Users should disable this feature in Nvidia's control panel to restore normal functionality(319115).
A partial list of changes is available in the SVN log. Interested in switching release channels? Find out how. If you find a new issue, please let us know by filing a bug.
This release fixes a number of crashes and other bugs. A full list of changes is available in the SVN log. Interested in switching release channels? Find out how. If you find a new issue, please let us know by filing a bug.