Google first to patch Flash bug with Chrome update
Takes advantage of deal with Adobe to push zero-day fix a week before others get protection
Computerworld - Google on Tuesday updated Chrome, patching a flaw in the browser's copy of Flash Player.
The move let Chrome beat rival browsers to the punch: Users of Internet Explorer (IE), Firefox, Safari and Opera won't receive a Flash update from Adobe until next week.
On Monday, Adobe announced that attackers are exploiting an unpatched, or "zero-day," vulnerability in Flash Player using malicious Microsoft Excel documents attached to e-mail messages. Adobe said it would patch Flash Player for Windows, Mac OS X and Linux sometime next week, but did not put a date on the calendar.
Yesterday, Google pushed a Chrome update to users running the stable and beta builds of the browser.
"This release contains an updated version of the Adobe Flash player," Jason Kersey, a Chrome program manager, said in a Tuesday post to a Google blog.
After updating Chrome to version 10.0.648.134, the browser reports that it's running Flash Player 10.2.154.25, a step up from the 10.2.154.18 bundled with the last update of the browser.
Adobe confirmed today that Chrome's integrated copy of Flash includes the patch for the zero-day vulnerability.
"As part of our collaboration with Google, Google receives updated builds of Flash Player for integration and testing," said Adobe spokeswoman Wiebke Lipps today. "Once testing is completed for Google Chrome, the release is pushed via the Chrome auto-update mechanism."
Adobe is still testing the patched Flash Player across its full list of supported platforms, which range from Windows and Mac OS X to Linux and Android, Lipps said.
Google has been including fixes for Flash Player in its Chrome updates since April 2010. Chrome is the only browser to automatically update Flash Player with its own patch mechanism.
Chrome users have gotten the jump on others before when it comes to Flash fixes. Last September, for example, Google updated the browser, and delivered a patched Flash Player, three days before Adobe.
Chrome 10.0.648.134 with the patched Flash Player can be downloaded can be downloaded for Windows, Mac OS X and Linux from Google's Web site. Users already running the browser will be updated automatically.
Gregg Keizer covers Microsoft, security issues, Apple, Web browsers and general technology breaking news for Computerworld. Follow Gregg on Twitter at
@gkeizer or subscribe to Gregg's RSS feed
. His e-mail address is gkeizer@computerworld.com.
Browser wars
- Microsoft slams Google over iPhone, Mac privacy boner
- Mozilla commits to Metro version of Firefox on Windows 8
- Microsoft wraps up ads aimed at Google with IE9 pitch
- German gov't endorses Chrome as most secure browser
- Google's punishment of Chrome drops browser's share, says metrics firm
- Firefox 10 relieves add-on updating pain
- Mozilla OKs Firefox 10 launch this week
- Google patches several serious Chrome bugs
- Mozilla slows pace of Firefox 9 upgrades
- Google patches Chrome, beefs up malicious file blocking tech
Read more about Browsers in Computerworld's Browsers Topic Center.



- Excel 2010 Cheat Sheet
- Register for this Computerworld Insider Cheat Sheet and gain access to hundreds of premium content articles, guides, product reviews and more.
- ESG: Defining Tier One Storage in the Modern Data Center
- This report defines "tier-1" storage in the modern IT world and in the data centers and services that support it. What was a...
- ESG: Using HP's Converged Storage to Develop/Enhance Business Resiliency in VMware Environments
- In this report, Enterprise Strategy Group reviews how HP's portfolio of hardware, software, and services can provide the foundational support for VMware environments....
- HP 3PAR Storage Systems Designed for Mission Critical High Availability
- In this technical whitepaper, learn how HP 3PAR Storage Systems have been designed to deliver 99.999% and greater availability, bringing new possibilities to...
- Utility Storage - The Ideal Platform for Virtual and Cloud Computing
- Server virtualization has transformed corporate IT -- companies have enjoyed major cost savings and have gained flexibility and efficiency. But this has also...
- ESG Lab Review: Focus on Federated Workload Balancing, Asset Management, and Thin Provisioning
- This ESG Lab review documents hands-on testing of HP 3PAR Peer Motion Software's distributed volume management with a focus on federated workload balancing,... All Browsers White Papers
- The Higher-Bandwidth, Lower-Cost Connection of Choice: 10GBASE-T LAN on Motherboard
- Learn how Expedient, a cloud provider, is using 10 Gigabit Ethernet to boost its services and rein in costs.
- Banish Poor Application Performance
- End User Experience, 30-Min Webinar
Wed. March 21st ~ 11 AM ET
Are you ready to gain the proactive ability to rapidly respond... - Virtualization KnowledgeVault
- Virtualization initiatives are underway at most small and midsize businesses, but some unexpected challenges have prevented many organizations from achieving original goals. This...
- Mobility KnowledgeVault
- How "mobile ready" is your infrastructure? This Mobility Knowledge Vault provides a wide variety of expert advice on how to strike a balance...
- Integrated IT Operations Management in the Cloud
- Join award-winning technology editor Stan Gibson and Andrew White, CMO at BMC, to learn how asset management and service management are converging and... All Browsers Webcasts
