Google patches Chrome for second time this month

Updates Windows version, pays bug bounties to researchers

Google patched three vulnerabilities in the Windows version of Chrome earlier in the week, marking the second time that it's plugged security holes this month.

Tuesday's update to Chrome 4.1.249.1064 fixed three flaws rated "high," the second-most-severe threat ranking in Google's four-step system. Danish vulnerability tracker Secunia rated the update as "highly critical" using its own severity ranking.

As is Google's practice, technical details of the vulnerabilities were hidden from public view, a tactic the company uses to prevent attackers from accessing the information until the majority of users have updated to the new version.

Researchers credited with reporting two of the flaws were awarded bonuses as part of Google's bug bounty program , which kicked off in January. Most flaws earn their finders $500, but researcher Jordi Chancel was handed $1,000 for the cross-origin bypass vulnerability he found in Chrome's handling of Google URL, a code library used to parse large numbers of Web addresses.

Chancel has also caught bugs in other browsers . Last December, for example, Mozilla patched a URL-spoofing flaw Chancel found in Firefox.

Google patched the Windows "stable" channel -- a term Google uses in place of "final" -- but left the Mac and Linux versions of Chrome untouched, as they have not yet left the "beta" channel.

The update was the second in two weeks for Chrome: Google also patched the Windows edition on April 20, quashing seven vulnerabilities , four of them ranked "high" and three labeled "medium," the next-lowest rating. Most of those flaws had been found by Google's own security engineers, but the company paid out $500 each to two outside researchers for reporting bugs.

Google typically patches Chrome more frequently than rivals such as Microsoft and Mozilla, in part because the browser updates itself silently in the background without notifying the user. Chrome has been patched five times so far this year, while Microsoft has updated Internet Explorer twice in 2010, both times with emergency patches to close holes that hackers were already exploiting. Mozilla has also patched Firefox twice this year.

Chrome is the world's third-most-popular browser, accounting for approximately 6% of the browsers in use, according to the most recent numbers from Web metrics company NetApplications.

Google Chrome can be downloaded for Windows XP, Vista and Windows 7 from the company's site. Users running the stable build will receive the update automatically.

Gregg Keizer covers Microsoft, security issues, Apple, Web browsers and general technology breaking news for Computerworld . Follow Gregg on Twitter at @gkeizer or subscribe to Gregg's RSS feed . His e-mail address is gkeizer@ix.netcom.com .

Join the newsletter!

Error: Please check your email address.
Rocket to Success - Your 10 Tips for Smarter ERP System Selection

Tags securityGoogle Chromesecurity patchweb browsers

Keep up with the latest tech news, reviews and previews by subscribing to the Good Gear Guide newsletter.

Gregg Keizer

Computerworld (US)
Show Comments

Cool Tech

Breitling Superocean Heritage Chronographe 44

Learn more >

SanDisk MicroSDXC™ for Nintendo® Switch™

Learn more >

Toys for Boys

Family Friendly

Panasonic 4K UHD Blu-Ray Player and Full HD Recorder with Netflix - UBT1GL-K

Learn more >

Stocking Stuffer

Razer DeathAdder Expert Ergonomic Gaming Mouse

Learn more >

Christmas Gift Guide

Click for more ›

Most Popular Reviews

Latest Articles

Resources

PCW Evaluation Team

Edwina Hargreaves

WD My Cloud Home

I would recommend this device for families and small businesses who want one safe place to store all their important digital content and a way to easily share it with friends, family, business partners, or customers.

Walid Mikhael

Brother QL-820NWB Professional Label Printer

It’s easy to set up, it’s compact and quiet when printing and to top if off, the print quality is excellent. This is hands down the best printer I’ve used for printing labels.

Ben Ramsden

Sharp PN-40TC1 Huddle Board

Brainstorming, innovation, problem solving, and negotiation have all become much more productive and valuable if people can easily collaborate in real time with minimal friction.

Sarah Ieroianni

Brother QL-820NWB Professional Label Printer

The print quality also does not disappoint, it’s clear, bold, doesn’t smudge and the text is perfectly sized.

Ratchada Dunn

Sharp PN-40TC1 Huddle Board

The Huddle Board’s built in program; Sharp Touch Viewing software allows us to easily manipulate and edit our documents (jpegs and PDFs) all at the same time on the dashboard.

George Khoury

Sharp PN-40TC1 Huddle Board

The biggest perks for me would be that it comes with easy to use and comprehensive programs that make the collaboration process a whole lot more intuitive and organic

Featured Content

Latest Jobs

Don’t have an account? Sign up here

Don't have an account? Sign up now

Forgot password?