Google fixes 22 flaws in Chrome, slams silent add-ons
Also yanks MathML, which just made it into Chrome last month, over security concerns
Computerworld - Google yesterday released Chrome 25, patching 22 vulnerabilities and debuting a new security feature that blocks silent installations of add-ons.
The latter is Chrome 25's most noticeable change to users. It automatically disables third-party add-ons that are installed on the sly by other software. Add-ons -- Google calls them "extensions" -- that were previously installed by third-party software will also be barred from running.
Users can approve a silent-installed extension by clicking a button in the dialog box that appears when Chrome blocks the add-on.
Google's move follows a similar one made by Mozilla more than a year ago, when it, too, crippled silently-installed add-ons. In November 2011, Mozilla debuted Firefox 8, which automatically blocked browser add-ons installed by other software.
Although silent add-ons have historically been more of a problem for Firefox than for Chrome, Google has been limiting add-ons since July 2012, when Chrome 21 began blocking add-ons hosted on a third-party website. Since then, only add-ons obtained from the Chrome Web Store, Google's official distribution mart, have been allowed.
Website designers can, however, trigger an add-on install from their URL using what Google dubbed "inline installation." The actual add-on, however, is still hosted on the Chrome Web Store.
Silent add-on installation has been possible only on Windows; OS X and Linux do not offer slippery websites a way to sneak an add-on into a browser.
The new version also adds the Web Speech API (application programming interface) that lets website and Web app developers add speech recognition features in their creations. Web Speech API is based on JavaScript, one of the Internet's foundational scripting languages.
Google has created a dictation demonstration of the Web Speech API that users can try out with Chrome 25.
Chrome 25 also patched 22 vulnerabilities, two fewer than January's Chrome 24. Google labeled nine of the flaws as "high," the company's second-most-serious threat rating, eight as "medium," and five as "low."
Five of the vulnerabilities were reported to Google by three outside researchers, who received $3,500 for their work. So far this year, Google has paid out $10,500 from its bug bounty program.
- 10 Hot Big Data Startups to Watch
- 11 Unique Uses for Google Glass, Demonstrated by Celebs
- How to Export Your Google Reader Account
- How to Better Engage Millennials (and Why They Aren't Really so Different)
- Telltale signs of ATM skimming
- 20 security and privacy apps for Androids and iPhones
- Big screen con artists: 7 great movies about social engineering
- IT Certification Study Tips
- Register for this Computerworld Insider Study Tip guide and gain access to hundreds of premium content articles, cheat sheets, product reviews and more.
- Is Your Service Desk Falling Behind? Read this use case document to understand how social IT collaboration can breathe new life into your existing service desk or ITSM installation...
- Three IT Imperatives CIOs Use To Drive Change Throughout the Enterprise CIOs who have been successful in bridging the divide between IT operations and business did it by accelerating the transformation of IT.
- Improving Change Management Through Collaboration Read this use case document to explore a real-world example of how social knowledge collaboration improves the accuracy and speed of change planning.
- Defending Against Today's Targeted Phishing Attacks Learn guidelines on how to recognize advanced threats and protect yourself from them.
- Virtustream (Vayence) video taking a 3000-Seat SAP Environment to the Cloud How can public cloud services help your organization reduce costs and increase security for your mission
- Williams & Fudge on Transforming IT with EMC Watch Williams & Fudge Data Center Director Phillip Reynolds discuss why this accounts receivable management firm turned to EMC. All Internet White Papers | Webcasts