Google Chrome updates

Chrome 42.0.2311.135 released

FYI...

Chrome 42.0.2311.135 released
- http://googlechromereleases.blogspot.com/2015/04/stable-channel-update_28.html
April 28, 2015 - "The stable channel has been updated to 42.0.2311.135 for Windows, Mac and Linux... This update includes -5- security fixes..."

Note: Access to bug details and links may be kept restricted until a majority of users are updated with a fix. We will also retain restrictions if the bug exists in a third party library that other projects similarly depend on, but haven’t yet fixed.
___

- https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2015-1243 - 7.5 (HIGH)

:fear::fear:
 
Last edited:
Chrome 43.0.2357.65 released

FYI...

Chrome 43.0.2357.65 released
- http://googlechromereleases.blogspot.com/2015/05/stable-channel-update_19.html
May 19, 2015 - "The Chrome team is happy to announce the promotion of Chrome 43 to the stable channel for Windows, Mac and Linux. Chrome 43.0.2357.65 contains a number of fixes and improvements... This update includes -37- security fixes..."
___

- https://www.us-cert.gov/ncas/current-activity/2015/05/19/Google-Releases-Security-Update-Chrome
May 19, 2015
___

- http://www.securitytracker.com/id/1032375
CVE Reference: CVE-2015-1251, CVE-2015-1252, CVE-2015-1253, CVE-2015-1254, CVE-2015-1255, CVE-2015-1256, CVE-2015-1257, CVE-2015-1258, CVE-2015-1259, CVE-2015-1260, CVE-2015-1261, CVE-2015-1262, CVE-2015-1263, CVE-2015-1264, CVE-2015-1265
May 21 2015
Impact: Disclosure of authentication information, Disclosure of user information, Execution of arbitrary code via network, Modification of user information, User access via network
Fix Available: Yes Vendor Confirmed: Yes
Version(s): prior to 43.0.2357.65 ...

:fear:
 
Last edited:
Chrome v43.0.2357.130 released

FYI...

Chrome v43.0.2357.130 released
- http://googlechromereleases.blogspot.com/2015/06/chrome-stable-update.html
June 22, 2015 - "The stable channel has been updated to 43.0.2357.130 for Windows, Mac, and Linux. A partial list of changes is available in the log... Access to bug details and links may be kept restricted until a majority of users are updated with a fix. We will also retain restrictions if the bug exists in a third party library that other projects similarly depend on, but haven’t yet fixed.
Below, we highlight 4 fixes that were contributed by external researchers...
High CVE-2015-1266: Scheme validation error in WebUI. Credit to anonymous.
High CVE-2015-1268: Cross-origin bypass in Blink. Credit to Mariusz Mlynski.
Medium CVE-2015-1267: Cross-origin bypass in Blink. Credit to anonymous.
Medium CVE-2015-1269: Normalization error in HSTS/HPKP preload list. Credit to Mike Ruddy..."

:fear:
 
Chrome 43.0.2357.132 released

FYI...

Chrome 43.0.2357.132 released
- http://googlechromereleases.blogspot.com/2015_07_01_archive.html
July 7, 2015 - "The stable channel has been updated to 43.0.2357.132 for Windows, Mac, and Linux..."

... comments:
- July 08, 2015
> "... this version of Chrome does include Flash 18.0.0.203"
> "... the schedule has Chrome 44 arriving July 14, 2015, with Chrome 45 following in early September (1st or 8th)."

:fear::fear:
 
Last edited:
Chrome 44.0.2403.89 released

FYI...

Chrome 44.0.2403.89 released
- http://googlechromereleases.blogspot.com/2015/07/stable-channel-update_21.html
July 21, 2015 - "... announcing the promotion of Chrome 44 to the stable channel for Windows, Mac and Linux. Chrome 44.0.2403.89 contains a number of fixes and improvements... This update includes -43- security fixes..."
___

- http://www.securitytracker.com/id/1033031
CVE Reference: CVE-2015-1270, CVE-2015-1271, CVE-2015-1272, CVE-2015-1273, CVE-2015-1274, CVE-2015-1275, CVE-2015-1276, CVE-2015-1277, CVE-2015-1278, CVE-2015-1279, CVE-2015-1280, CVE-2015-1281, CVE-2015-1282, CVE-2015-1283, CVE-2015-1284, CVE-2015-1285, CVE-2015-1286, CVE-2015-1287, CVE-2015-1288, CVE-2015-1289, CVE-2015-5605
Jul 23 2015
Impact: Disclosure of authentication information, Disclosure of system information, Disclosure of user information, Execution of arbitrary code via network, Modification of system information, Modification of user information, User access via network
Fix Available: Yes Vendor Confirmed: Yes
Version(s): prior to 44.0.2403.89 ...

:fear::fear:
 
Chrome 44.0.2403.107 released

FYI...

Chrome 44.0.2403.107 released
- http://googlechromereleases.blogspot.com/2015/07/stable-channel-update_24.html
July 24, 2015 - "The stable channel has been updated to 44.0.2403.107 for Windows, Mac and Linux. A partial list of changes is available in the log*..."
* https://chromium.googlesource.com/c....2403.89..44.0.2403.107?pretty=fuller&n=10000

> http://googleprojectzero.blogspot.com/2015/07/significant-flash-exploit-mitigations_16.html
July 16, 2015 - "... if you're running Google Chrome, you can visit about:version to check the versions of various components. If you have Flash v18.0.0.209 (or newer), then you have the new goodies. If not, you can (on Windows) visit chrome://chrome to give the autoupdater a kick..."

:fear:
 
Last edited:
Chrome 44.0.2403.155 released

FYI...

Chrome 44.0.2403.155 released
- http://googlechromereleases.blogspot.com/2015/08/stable-channel-update_11.html
Aug 11, 2015 - "The stable channel has been updated to 44.0.2403.155 for Windows, Mac, and Linux..."
Comments: "... automatic update not working*"

* http://googleprojectzero.blogspot.com/2015/07/significant-flash-exploit-mitigations_16.html
"... if you're running Google Chrome, you can visit about:version to check the versions of various components... you can (on Windows) visit chrome://chrome to give the autoupdater a kick..."

:fear::fear:
 
Chrome 45.0.2454.85 released

FYI...

Chrome 45.0.2454.85 released
- http://googlechromereleases.blogspot.com/2015/09/stable-channel-update.html
Sep 1, 2015 - "... Chrome 45.0.2454.85 contains a number of fixes and improvements - a list of changes is available in the log... This update includes -29- security fixes..."

- https://www.us-cert.gov/ncas/current-activity/2015/09/01/Google-Releases-Security-Update-Chrome
Sep 1, 2015
___

- http://www.securitytracker.com/id/1033472
CVE Reference: CVE-2015-1291, CVE-2015-1292, CVE-2015-1293, CVE-2015-1294, CVE-2015-1295, CVE-2015-1296, CVE-2015-1297, CVE-2015-1298, CVE-2015-1299, CVE-2015-1300, CVE-2015-1301, CVE-2015-6580, CVE-2015-6581, CVE-2015-6582, CVE-2015-6583
Sep 4 2015
Impact: Disclosure of system information, Disclosure of user information, Execution of arbitrary code via network, Modification of user information, User access via network
Fix Available: Yes Vendor Confirmed: Yes ...
Solution: The vendor has issued a fix (45.0.2454.85)...

:fear::fear:
 
Last edited:
Chrome 45.0.2454.101 released

FYI...

Chrome 45.0.2454.101 released
- http://googlechromereleases.blogspot.com/2015/09/stable-channel-update_24.html
Sep 24, 2015 - "The stable channel has been updated to 45.0.2454.101 for Windows, Mac, and Linux...
Note: Access to bug details and links may be kept restricted until a majority of users are updated with a fix..."

- https://www.us-cert.gov/ncas/current-activity/2015/09/25/Google-Release-Security-Update-Chrome-0
Sep 25, 2015 - "Google has released Chrome version 45.0.2454.101 to address multiple vulnerabilities for Windows, Mac, and Linux. Exploitation of one of these vulnerabilities may allow a remote attacker to obtain sensitive information from an affected system..."
___

- http://www.securitytracker.com/id/1033683
CVE Reference: CVE-2015-1303, CVE-2015-1304
Sep 30 2015
Impact: Disclosure of system information, Disclosure of user information, Modification of system information, Modification of user information
Fix Available: Yes Vendor Confirmed: Yes
Version(s): prior to 45.0.2454.101 ...
Impact: A remote user can bypass cross-origin security controls on the target system.
Solution: The vendor has issued a fix (45.0.2454.101)...

:fear::fear:
 
Last edited:
Chrome 46.0.2490.71 released

FYI...

Chrome 46.0.2490.71 released
- http://googlechromereleases.blogspot.com/2015/10/stable-channel-update.html
Oct 13, 2015 - "... promotion of Chrome 46 to the stable channel for Windows, Mac and Linux... Chrome 46.0.2490.71 contains a number of fixes and improvements...
Note: Access to bug details and links may be kept restricted until a majority of users are updated with a fix. We will also retain restrictions if the bug exists in a third party library that other projects similarly depend on, but haven’t yet fixed.
This update includes -24- security fixes..."
___

Stable Channel Updates
> http://googlechromereleases.blogspot.com/2015/10/stable-channel-update.html
___

- https://www.us-cert.gov/ncas/current-activity/2015/10/13/Google-Releases-Security-Update-Chrome
Oct 13, 2015
___

- http://www.securitytracker.com/id/1033816
CVE Reference: CVE-2015-6755, CVE-2015-6756, CVE-2015-6757, CVE-2015-6758, CVE-2015-6759, CVE-2015-6760, CVE-2015-6761, CVE-2015-6762, CVE-2015-6763
Oct 15 2015
Fix Available: Yes Vendor Confirmed: Yes
Version(s): prior to 46.0.2490.71 ...
Solution: The vendor has issued a fix (46.0.2490.71) ...

:fear::fear:
 
Last edited:
Chrome 46.0.2490.86 released

FYI...

Chrome 46.0.2490.86 released
- http://googlechromereleases.blogspot.fr/2015/11/stable-channel-update.html
Nov 10, 2015 - "The stable channel has been updated to 46.0.2490.86 for Windows, Mac, and Linux. This release contains an update to Adobe Flash Player (19.0.0.245) and security fixes..."
___

- http://www.computerworld.com/articl...f-chrome-updates-on-windows-xp-and-vista.html
Nov 10, 2015 - "... PCs running XP and Vista will be able to keep using Chrome after April 2016, but Google will cease providing -updates- to its browser*, including security-focused patches..."
* http://chrome.blogspot.com/2015/11/updates-to-chrome-platform-support.html

:fear::fear:
 
Last edited:
Chrome 47.0.2526.73 released

FYI...

Chrome 47.0.2526.73 released
- http://googlechromereleases.blogspot.com/2015/12/stable-channel-update.html
Dec 1, 2015 - " The Chrome team is delighted to announce the promotion of Chrome 47 to the stable channel for Windows, Mac and Linux. Chrome 47.0.2526.73 contains a number of fixes and improvements...
Note: Access to bug details and links may be kept restricted until a majority of users are updated with a fix. We will also retain restrictions if the bug exists in a third party library that other projects similarly depend on, but haven’t yet fixed.
This update includes -41- security fixes..."

- https://www.us-cert.gov/ncas/current-activity/2015/12/01/Google-Releases-Security-Update-Chrome
Dec 1, 2015
___

- http://www.securitytracker.com/id/1034298
CVE Reference: CVE-2015-6764, CVE-2015-6765, CVE-2015-6766, CVE-2015-6767, CVE-2015-6768, CVE-2015-6769, CVE-2015-6770, CVE-2015-6771, CVE-2015-6772, CVE-2015-6773, CVE-2015-6774, CVE-2015-6775, CVE-2015-6776, CVE-2015-6777, CVE-2015-6778, CVE-2015-6779, CVE-2015-6780, CVE-2015-6781, CVE-2015-6782, CVE-2015-6783, CVE-2015-6784, CVE-2015-6785, CVE-2015-6786, CVE-2015-6787
Dec 7 2015
Fix Available: Yes Vendor Confirmed: Yes
Version(s): prior to 47.0.2526.73 ...
Impact: A remote user can execute arbitrary code on the target system.
A remote user can bypass security controls on the target system.
A remote user can spoof content.
Solution: The vendor has issued a fix (47.0.2526.73).
The vendor's advisory is available at:
- http://googlechromereleases.blogspot.com/2015/12/stable-channel-update.html

:fear::fear:
 
Last edited:
Chrome 47.0.2526.80 released

FYI...

Chrome 47.0.2526.80 released
- http://googlechromereleases.blogspot.com/2015/12/stable-channel-update_8.html
Dec 8, 2015 - "The stable channel has been updated to 47.0.2526.80 for Windows, Mac, and Linux. This release contains an update to Adobe Flash Player (20.0.0.228) and security fixes...
This update includes -7- security fixes..."
___

- https://www.us-cert.gov/ncas/current-activity/2015/12/08/Google-Releases-Security-Update-Chrome
Dec 08, 2015

:fear::fear:
 
Last edited:
Chrome 47.0.2526.106 released

FYI...

Chrome 47.0.2526.106 released
- http://googlechromereleases.blogspot.com/2015/12/stable-channel-update_15.html
Dec 15, 2015 - "The stable channel has been updated to 47.0.2526.106 for Windows, Mac, and Linux.
Security Fixes
Note: Access to bug details and links may be kept restricted until a majority of users are updated with a fix. We will also retain restrictions if the bug exists in a third party library that other projects similarly depend on, but haven’t yet fixed.
This update includes -2- security fixes as part of our ongoing internal security work..."

- https://www.us-cert.gov/ncas/current-activity/2015/12/15/Google-Releases-Security-Update-Chrome
Dec 15, 2015
___

- http://www.securitytracker.com/id/1034491
CVE Reference: CVE-2015-6792
Dec 18 2015
Description: Two vulnerabilities were reported in Google Chrome. A remote user can cause arbitrary code to be executed on the target user's system.
A remote user can create specially crafted content that, when loaded by the target user, will execute arbitrary code on the target user's system.
Impact: A remote user can create content that, when loaded by the target user, will execute arbitrary code on the target user's system.
Solution: The vendor has issued a fix (47.0.2526.106)...

:fear:
 
Last edited:
Back
Top