Google patches several serious Chrome bugs
Critical vulnerability disclosed Monday was actually fixed earlier this month
Computerworld - Google yesterday patched four vulnerabilities in Chrome, and disclosed that it had patched a fifth two weeks ago.
The refresh of Chrome 16 was the second security-related update for the browser this month.
One of the five bugs Google said had been quashed was actually a leftover from the Jan. 9 update. According to a blog post by Anthony Laforge, a Chrome program manager, that flaw was actually patched two weeks ago, but "[was] accidentally excluded from the release notes" at the time.
The vulnerability was the most serious of the five, rating a "critical" ranking, Google's top threat label.
According to the bug-tracking materials for Chromium, the open-source project that feeds code into Chrome, the critical bug caused the browser to crash when users saw Chrome's anti-malicious site warning and then refreshed the page.
Researcher Chamal de Silva reported the vulnerability in mid-December 2011, and was awarded $3,133 -- Google's highest bounty -- for his work. de Silva's bug was only the third time Google has paid out the $3,133 maximum, and the first time since June 2011.
In July 2010, Google boosted its top dollar bounty from $1,337 to $3,133, making the move less than a week after rival Mozilla increased Firefox bug bounties to $3,000.
Two other researchers who reported three of the remaining vulnerabilities were paid a total of $3,000 in bounties. Those bugs were rated as "high" threats.
Google has paid out more than $8,000 so far this year to independent researchers for filing bug reports. Last year, the search giant spent more than $180,000 on bounties.
Chrome accounted for 19.1% of all browsers used last month, a record for Google, according to Web metrics firm Net Application. If its share movement continues on past pace, Chrome will crack the 20% mark either this month or next.
Chrome 16, the current stable edition, can be downloaded from Google's website.
Gregg Keizer covers Microsoft, security issues, Apple, Web browsers and general technology breaking news for Computerworld. Follow Gregg on Twitter at
@gkeizer, on Google+ or subscribe to Gregg's RSS feed
. His e-mail address is gkeizer@computerworld.com.
See more articles by Gregg Keizer.
Browser wars
- Microsoft slams Google over iPhone, Mac privacy boner
- Mozilla commits to Metro version of Firefox on Windows 8
- Microsoft wraps up ads aimed at Google with IE9 pitch
- German gov't endorses Chrome as most secure browser
- Google's punishment of Chrome drops browser's share, says metrics firm
- Firefox 10 relieves add-on updating pain
- Mozilla OKs Firefox 10 launch this week
- Google patches several serious Chrome bugs
- Mozilla slows pace of Firefox 9 upgrades
- Google patches Chrome, beefs up malicious file blocking tech
Read more about Browsers in Computerworld's Browsers Topic Center.



- Excel 2010 Cheat Sheet
- Register for this Computerworld Insider Cheat Sheet and gain access to hundreds of premium content articles, guides, product reviews and more.
- ESG: Defining Tier One Storage in the Modern Data Center
- This report defines "tier-1" storage in the modern IT world and in the data centers and services that support it. What was a...
- ESG: Using HP's Converged Storage to Develop/Enhance Business Resiliency in VMware Environments
- In this report, Enterprise Strategy Group reviews how HP's portfolio of hardware, software, and services can provide the foundational support for VMware environments....
- HP 3PAR Storage Systems Designed for Mission Critical High Availability
- In this technical whitepaper, learn how HP 3PAR Storage Systems have been designed to deliver 99.999% and greater availability, bringing new possibilities to...
- Utility Storage - The Ideal Platform for Virtual and Cloud Computing
- Server virtualization has transformed corporate IT -- companies have enjoyed major cost savings and have gained flexibility and efficiency. But this has also...
- ESG Lab Review: Focus on Federated Workload Balancing, Asset Management, and Thin Provisioning
- This ESG Lab review documents hands-on testing of HP 3PAR Peer Motion Software's distributed volume management with a focus on federated workload balancing,... All Browsers White Papers
- The Higher-Bandwidth, Lower-Cost Connection of Choice: 10GBASE-T LAN on Motherboard
- Learn how Expedient, a cloud provider, is using 10 Gigabit Ethernet to boost its services and rein in costs.
- Banish Poor Application Performance
- End User Experience, 30-Min Webinar
Wed. March 21st ~ 11 AM ET
Are you ready to gain the proactive ability to rapidly respond... - Virtualization KnowledgeVault
- Virtualization initiatives are underway at most small and midsize businesses, but some unexpected challenges have prevented many organizations from achieving original goals. This...
- Mobility KnowledgeVault
- How "mobile ready" is your infrastructure? This Mobility Knowledge Vault provides a wide variety of expert advice on how to strike a balance...
- Integrated IT Operations Management in the Cloud
- Join award-winning technology editor Stan Gibson and Andrew White, CMO at BMC, to learn how asset management and service management are converging and... All Browsers Webcasts
