Adobe drags Google into Microsoft's Patch Tuesday
Adobe's decision to fix Flash on Patch Tuesday forces Google to update Chrome the same day
Computerworld - Google has been dragged into adopting rival Microsoft's Patch Tuesday, fallout from an Adobe move last month.
Earlier this week, Google updated its Chrome browser, quashing six bugs and as it often does, also updating Adobe's Flash Player. That same day, Microsoft shipped seven security updates to patch 12 vulnerabilities, and Adobe released a new version of Flash to address three critical bugs.
It was the Flash patches that triggered Chrome's copycat update: In November, Adobe announced it would synchronize Flash updates with long-time-partner Microsoft's Patch Tuesday. Most security experts applauded the decision, which they said was prompted by the bundling of Flash with Internet Explorer 10 (IE10) on Windows 8 and Windows RT.
Those same experts said Adobe's hand was probably forced by Microsoft, which had bumbled this fall when it failed to sync IE10 updates with those shipped by Adobe for Flash.
But because Google also bakes Flash Player into Chrome, Adobe's Patch Tuesday adoption also requires Google to ship updates the same day or put its users at risk.
Chrome has included Flash since April 2010, and is regularly updated whenever Adobe patches the popular media player.
Security professionals praised the three-vendor synchronization on the month's most important patch day.
"We already knew that Microsoft was the leader in security patch cadence, so for others to fall in line was inevitable," said Andrew Storms, director of security operations, in an instant message interview. "I suspect the more this happens, the more vendors will want to coordinate. It really is better for both them and customers if everyone knows a patch is imminent."
Jason Miller, manager of research and development at VMware, concurred. "It's good to see vendors coordinate like this," he said in an interview earlier this week.
But even more could be done.
"The biggest win [for users] is if all the vendors provided an advance notification so security teams could plan accordingly," he said. "Without proper notice, we are really in the same boat as before, where the surprise updates catch you off guard."
Adobe does not offer pre-patch notifications for Flash -- it does for Adobe Reader and Acrobat, however -- and neither does Google for Chrome.
Although Google patched Chrome on Tuesday -- and also on last month's Patch Tuesday of Nov. 13 -- it does not hew to a Patch Tuesday-only schedule, as Microsoft and Adobe do for all but emergency updates. Typically, Chrome is patched several times each month, on no set schedule. In the month between the last two Patch Tuesdays, for instance, Google updated Chrome twice.
The six Chrome patches Google provided Dec. 11 included three reported by independent researchers, who were awarded a total of $4,500 in bounty payments. So far this year, Google has paid more than $380,000 in Chrome bounties.
Chrome is automatically updated in the background each time Google patches the browser. The newest version can also be downloaded from Google's website for Windows, OS X and Linux.
Gregg Keizer covers Microsoft, security issues, Apple, Web browsers and general technology breaking news for Computerworld. Follow Gregg on Twitter at
@gkeizer, on Google+ or subscribe to Gregg's RSS feed
. His email address is gkeizer@computerworld.com.
See more by Gregg Keizer on Computerworld.com.
Security alert
- Popular home routers contain critical security vulnerabilities
- IT security managers too focused on compliance, experts say
- Microsoft patches IE with record-setting updates to prep browser for Pwn2Own
- Adobe releases emergency Flash fixes for two zero-day bugs
- 'Andyhave3cats' is a better password than 'Shehave3cats,' study finds
- 'Bob' outsources tech job to China; watches cat videos at work
- Oracle rushes patch to quash critical Java bugs
- Project Blitzkrieg e-banking heist is a credible threat, McAfee says
- Adobe drags Google into Microsoft's Patch Tuesday
- Microsoft quashes critical bugs in IE10, Windows 8, Word
Read more about Security in Computerworld's Security Topic Center.
- Google I/O 2013's Coolest Products and Services
- 10 Star Trek Technologies That are Almost Here
- 19 Generations of Computer Programmers
- 25 Must-Have Technologies for SMBs
- A walking tour: 33 questions to ask about your company's security
- 15 social media scams
- The 7 elements of a successful security awareness program
- IT Certification Study Tips
- Register for this Computerworld Insider Study Tip guide and gain access to hundreds of premium content articles, cheat sheets, product reviews and more.
- Best Practices for Cloud-based Information Governance This paper explores the latest ideas on evaluating cloud deployment: public or private clouds, data location and privacy, data ownership and access, and...
- Social Media and the Shifting Information Compliance Landscape Packed with practical advice, the white paper includes a 'model solution for social media' that outlines four best practices to help information professionals...
- Meet your Dodd-Frank recordkeeping compliance requirements Download this white paper for IT professionals to learn about a DFA solution that enables any financial organization to harness existing IT investments...
- Protection for Every Enterprise: How BlackBerry 10 Security Works Get an IT-level review of BlackBerry® 10 Security, addressing data leakage protection, certified encryption, containerization and much more.
- Live Webcast
Storage Validation at Go Daddy: Best Practices from the World's #1 Web Hosting Provider - Storage Validation at Go Daddy: Best Practices from the World's #1 Web Hosting Provider
- Live Webcast
MFT and FileXpress - An Overview - Business users and applications exchange files on a regular basis. File transfer is a core part of the flow of business activity.
- Live Webcast
Bridging HTTP and FTP with FileXpress Internet Server - What if you could take an FTP server on your internal network, and allow external users (partners or customers) to securely access it...
- Bridging HTTP and FTP with FileXpress Internet Server What if you could take an FTP server on your internal network, and allow external users (partners or customers) to securely access it...
- MFT and FileXpress - An Overview Business users and applications exchange files on a regular basis. File transfer is a core part of the flow of business activity. All Security White Papers | Webcasts
