Google ships Chrome 17, touts more malware alerts and page preloads
Patches 20 vulnerabilities, pays $10,500 in bounties to four bug hunters
Computerworld - Google today patched 20 vulnerabilities in the desktop edition of Chrome and added new anti-malware download warnings to version 17.
The company called out a pair of new features in Chrome 17, including the expansion of anti-malware download warnings and prerendering of pages suggested by the address/search bar's auto-complete function.
Google last refreshed Chrome eight weeks ago, on Dec. 13. Google generates an update to its "stable" channel about every six to eight weeks, a slightly more flexible schedule than rival Mozilla's every-six-weeks pace.
One of the 20 vulnerabilities patched today was rated "critical," the most dire ranking in Google's threat system. Eight were marked "high," while five were labeled "medium" and six were tagged "low."
Google paid $10,500 in bounties to four researchers for reporting 11 bugs, and another $3,133 to one of the four who uncovered a serious flaw that was quashed by developers before Chrome 17 made it to today's release. The nine other vulnerabilities were uncovered by members of Google's own security team, which includes developers who contribute to the open-source Chromium project -- which feeds code to Chrome -- or those who, for one reason or other, were not bonus-eligible.
Per its usual practice, Google blocked access to its bug tracking database for all 20 vulnerabilities to prevent outsiders from obtaining details that could be used to build exploits. Google typically opens up the database weeks or even months later, after it's sure a majority of users have migrated to the new edition.
Google typically includes a handful of obvious changes in each Chrome upgrade, and it stayed with that practice today: The two features visible to users were an extension of Chrome's long-running anti-malware download warnings and faster displaying of some Web pages.
The new download warnings alert users when they try to retrieve executable Windows files -- including those with the ".exe" and ".msi" extensions -- that Google knows or suspects are malicious, or are hosted on a website that commonly distributes threats.
Such warnings have been part of Chrome since version 12, which launched in June 2011, but they've been expanded in Chrome 17.
If the file isn't a known quantity or isn't from a reputable publisher, information about the file is sent to Google, which runs it through an analyzer to rank its "reputation and trustworthiness [compared to] files previously seen from the same publisher and website," said the company last month.
Suspicious files -- ones that match the criteria of others known to come from the same source -- are tagged, and if there's a high probability that it's malicious, the user sees an alert.


- Excel 2010 Cheat Sheet
- Register for this Computerworld Insider Cheat Sheet and gain access to hundreds of premium content articles, guides, product reviews and more.
- How Blade Centers Impact Data Center Management and Agility
- This paper examines enterprise adoption of blade servers in the US, UK and China; the benefits of blade server use; and the connection...
- Nemertes Research PilotHouse Awards: Server for Virtualization
- The Nemertes Research PilotHouse Awards provide insight on the performance of technology vendors, according to feedback from IT decision makers who use their...
- Gartner Magic Quadrant for Blade Servers
- The market for blade servers is becoming ever more complex and diverse due to the convergence of related modular form factors, a fast-growing...
- Real Fabrics for a Virtual World
- Many factors influence what "ideal" approach organizations should take when planning to implement a fabric-based infrastructure policy. This presentation charts the likely evolution...
- Picking the Right Server solution to solve your Space, Power and Cooling problems
- The type of server you install in a data center can have a big impact -- positive or negative -- on the space,... All Browsers White Papers
- Today's NAS: A Solution Beyond Old Limits
- Date: Tuesday, July 17, 2012 2:00 PM EDT
Traditional NAS systems don't scale beyond fixed limits. Proliferation of NAS systems leads to management... - Redefine Expectations in the Data Center
- Need to do more with less? Watch this video to learn how HP ProLiant Gen8 servers can help your business deploy servers three...
- Oracle Database Appliance Best Practices
- Business users increasingly demand 24x7 availability of their data while IT departments face the challenge of ensuring maximum availability while operating with limited...
- Data Privacy and Protection in Production Environments: New Research from Ponemon Institute
- Date: Wednesday, June 13, 2012, 1:00 PM EDT / 10:00 AM PDT
In a recent study conducted by Ponemon Institute, fifty-five percent of respondents... - BMC Control-M - Single Point of Control Demo
- With BMC Control-M, you schedule and manage everything - down to the very last platform and application - from one simple interface. It's... All Browsers Webcasts