Google patches Chrome for second time this month

Updates Windows version, pays bug bounties to researchers

Google patched three vulnerabilities in the Windows version of Chrome earlier in the week, marking the second time that it's plugged security holes this month.

Tuesday's update to Chrome 4.1.249.1064 fixed three flaws rated "high," the second-most-severe threat ranking in Google's four-step system. Danish vulnerability tracker Secunia rated the update as "highly critical" using its own severity ranking.

As is Google's practice, technical details of the vulnerabilities were hidden from public view, a tactic the company uses to prevent attackers from accessing the information until the majority of users have updated to the new version.

Researchers credited with reporting two of the flaws were awarded bonuses as part of Google's bug bounty program , which kicked off in January. Most flaws earn their finders $500, but researcher Jordi Chancel was handed $1,000 for the cross-origin bypass vulnerability he found in Chrome's handling of Google URL, a code library used to parse large numbers of Web addresses.

Chancel has also caught bugs in other browsers . Last December, for example, Mozilla patched a URL-spoofing flaw Chancel found in Firefox.

Google patched the Windows "stable" channel -- a term Google uses in place of "final" -- but left the Mac and Linux versions of Chrome untouched, as they have not yet left the "beta" channel.

The update was the second in two weeks for Chrome: Google also patched the Windows edition on April 20, quashing seven vulnerabilities , four of them ranked "high" and three labeled "medium," the next-lowest rating. Most of those flaws had been found by Google's own security engineers, but the company paid out $500 each to two outside researchers for reporting bugs.

Google typically patches Chrome more frequently than rivals such as Microsoft and Mozilla, in part because the browser updates itself silently in the background without notifying the user. Chrome has been patched five times so far this year, while Microsoft has updated Internet Explorer twice in 2010, both times with emergency patches to close holes that hackers were already exploiting. Mozilla has also patched Firefox twice this year.

Chrome is the world's third-most-popular browser, accounting for approximately 6% of the browsers in use, according to the most recent numbers from Web metrics company NetApplications.

Google Chrome can be downloaded for Windows XP, Vista and Windows 7 from the company's site. Users running the stable build will receive the update automatically.

Gregg Keizer covers Microsoft, security issues, Apple, Web browsers and general technology breaking news for Computerworld . Follow Gregg on Twitter at @gkeizer or subscribe to Gregg's RSS feed . His e-mail address is gkeizer@ix.netcom.com .

Join the newsletter!

Or

Sign up to gain exclusive access to email subscriptions, event invitations, competitions, giveaways, and much more.

Membership is free, and your security and privacy remain protected. View our privacy policy before signing up.

Error: Please check your email address.

Tags Google Chromesecurity patchweb browsers

Keep up with the latest tech news, reviews and previews by subscribing to the Good Gear Guide newsletter.
Gregg Keizer

Gregg Keizer

Computerworld (US)
Show Comments

Cool Tech

Bang and Olufsen Beosound Stage - Dolby Atmos Soundbar

Learn more >

Toys for Boys

ASUS ROG, ACRONYM partner for Special Edition Zephyrus G14

Learn more >

Sony WF-1000XM3 Wireless Noise Cancelling Headphones

Learn more >

Nakamichi Delta 100 3-Way Hi Fi Speaker System

Learn more >

Family Friendly

Philips Sonicare Diamond Clean 9000 Toothbrush

Learn more >

Mario Kart Live: Home Circuit for Nintendo Switch

Learn more >

Stocking Stuffer

Teac 7 inch Swivel Screen Portable DVD Player

Learn more >

SunnyBunny Snowflakes 20 LED Solar Powered Fairy String

Learn more >

Christmas Gift Guide

Click for more ›

Most Popular Reviews

Latest Articles

Resources

PCW Evaluation Team

Tom Pope

Dynabook Portégé X30L-G

Ultimately this laptop has achieved everything I would hope for in a laptop for work, while fitting that into a form factor and weight that is remarkable.

Tom Sellers

MSI P65

This smart laptop was enjoyable to use and great to work on – creating content was super simple.

Lolita Wang

MSI GT76

It really doesn’t get more “gaming laptop” than this.

Jack Jeffries

MSI GS75

As the Maserati or BMW of laptops, it would fit perfectly in the hands of a professional needing firepower under the hood, sophistication and class on the surface, and gaming prowess (sports mode if you will) in between.

Taylor Carr

MSI PS63

The MSI PS63 is an amazing laptop and I would definitely consider buying one in the future.

Christopher Low

Brother RJ-4230B

This small mobile printer is exactly what I need for invoicing and other jobs such as sending fellow tradesman details or step-by-step instructions that I can easily print off from my phone or the Web.

Featured Content

Don’t have an account? Sign up here

Don't have an account? Sign up now

Forgot password?