04-19-2017 , 09:07 PM
https://chromereleases.googleblog.com/ Chrome Releases
Release updates from the Chrome team
Stable Channel Update for Desktop
Wednesday, April 19, 2017
The Chrome team is delighted to announce the promotion of Chrome 58 to the stable channel for Windows, Mac and Linux. This will roll out over the coming days/weeks.
Chrome 58.0.3029.81 contains a number of fixes and improvements -- a list of changes is available in the log. Watch out for upcoming Chrome and Chromium blog posts about new features and big efforts delivered in 58.
Security Fixes and Rewards
Note: Access to bug details and links may be kept restricted until a majority of users are updated with a fix. We will also retain restrictions if the bug exists in a third party library that other projects similarly depend on, but haven’t yet fixed.
This update includes 29 security fixes. Below, we highlight fixes that were contributed by external researchers. Please see the Chrome Security Page for more information.
[$3000][695826] High CVE-2017-5057: Type confusion in PDFium. Credit to Guang Gong of Alpha Team, Qihoo 360
[$2000][694382] High CVE-2017-5058: Heap use after free in Print Preview. Credit to Khalil Zhani
[$N/A][684684] High CVE-2017-5059: Type confusion in Blink. Credit to SkyLined working with Trend Micro's Zero Day Initiative
[$2000][683314] Medium CVE-2017-5060: URL spoofing in Omnibox. Credit to Xudong Zheng
[$2000][672847] Medium CVE-2017-5061: URL spoofing in Omnibox. Credit to Haosheng Wang (@gnehsoah)
[$1500][702896] Medium CVE-2017-5062: Use after free in Chrome Apps. Credit to anonymous
[$1000][700836] Medium CVE-2017-5063: Heap overflow in Skia. Credit to Sweetchip
[$1000][693974] Medium CVE-2017-5064: Use after free in Blink. Credit to Wadih Matar
[$500][704560] Medium CVE-2017-5065: Incorrect UI in Blink. Credit to Khalil Zhani
[$500][690821] Medium CVE-2017-5066: Incorrect signature handing in Networking. Credit to chenchu
[$500][648117] Medium CVE-2017-5067: URL spoofing in Omnibox. Credit to Khalil Zhani
[$N/A][691726] Low CVE-2017-5069: Cross-origin bypass in Blink. Credit to Michael Reizelman
We would also like to thank all security researchers that worked with us during the development cycle to prevent security bugs from ever reaching the stable channel.
As usual, our ongoing internal security work was responsible for a wide range of fixes:
[713205] Various fixes from internal audits, fuzzing and other initiatives
Many of our security bugs are detected using AddressSanitizer, MemorySanitizer, Control Flow Integrity, or libFuzzer.
Interested in switching release channels? Find out how. If you find a new issue, please let us know by filing a bug. The community help forum is also a great place to reach out for help or learn about common issues.
Krishna Govind
Google Chrome : https://www.google.com/chrome/browser/desktop/ Get a fast, free web browser
One browser for your computer, phone and tablet
Download Chrome
For Windows 10/8.1/8/7 64-bit
Download Chrome for another platform Browse faster Search instantly
Search and navigate from the same box. Choose from results and suggestions that appear as you type, including your recent searches and visited websites, so you can get to what you want in a snap. Search from the omnibox
Type less
Tired of filling out web forms with the same information time and time again? Autofill lets you complete forms with just one click. And it works across devices too — so you can skip all that small-screen typing. Start using Autofill
Pick up where you left off
Chrome brings your open tabs, bookmarks and recent searches from your computer to your phone or tablet, and vice versa. That way you have your web on all of your devices. Just sign in on your other devices to start syncing. Learn more
Make Chrome yours
Browse just the way you'd like with Chrome themes, apps and extentions. Get straight to your favorite web destinations with bookmarks and start pages. Once you've set up Chrome, your customizations will be kept in sync across all of your devices. Start customizing
https://www.virustotal.com/en/file/49fb0...492629245/ SHA256: 49fb0c816d80889422a5806df5e19ac6f069826484d5608773cde41f2ffb150d
File name: ChromeSetup.exe
Detection ratio: 0 / 60
Analysis date: 2017-04-19 19:14:05 UTC ( 11 minutes ago ) Copyright 2007-2010 Google Inc.
Product Google Update
Original name GoogleUpdateSetup.exe
Internal name Google Update Setup
File version 1.3.32.7
Description Google Update Setup
Signature verification Signed file, verified signature
Signing date 3:46 AM 12/8/2016
Signers
[+] Google Inc
[+] VeriSign Class 3 Code Signing 2010 CA
[+] VeriSign
Counter signers
[+] COMODO SHA-1 Time Stamping Signer
[+] USERTrust (Code Signing) VirusTotal metadata
First submission 2017-04-19 19:14:05 UTC ( 11 minutes ago )
Last submission 2017-04-19 19:14:05 UTC ( 11 minutes ago )
File names Google Update Setup
GoogleUpdateSetup.exe
ChromeSetup.exe
Release updates from the Chrome team
Stable Channel Update for Desktop
Wednesday, April 19, 2017
The Chrome team is delighted to announce the promotion of Chrome 58 to the stable channel for Windows, Mac and Linux. This will roll out over the coming days/weeks.
Chrome 58.0.3029.81 contains a number of fixes and improvements -- a list of changes is available in the log. Watch out for upcoming Chrome and Chromium blog posts about new features and big efforts delivered in 58.
Security Fixes and Rewards
Note: Access to bug details and links may be kept restricted until a majority of users are updated with a fix. We will also retain restrictions if the bug exists in a third party library that other projects similarly depend on, but haven’t yet fixed.
This update includes 29 security fixes. Below, we highlight fixes that were contributed by external researchers. Please see the Chrome Security Page for more information.
[$3000][695826] High CVE-2017-5057: Type confusion in PDFium. Credit to Guang Gong of Alpha Team, Qihoo 360
[$2000][694382] High CVE-2017-5058: Heap use after free in Print Preview. Credit to Khalil Zhani
[$N/A][684684] High CVE-2017-5059: Type confusion in Blink. Credit to SkyLined working with Trend Micro's Zero Day Initiative
[$2000][683314] Medium CVE-2017-5060: URL spoofing in Omnibox. Credit to Xudong Zheng
[$2000][672847] Medium CVE-2017-5061: URL spoofing in Omnibox. Credit to Haosheng Wang (@gnehsoah)
[$1500][702896] Medium CVE-2017-5062: Use after free in Chrome Apps. Credit to anonymous
[$1000][700836] Medium CVE-2017-5063: Heap overflow in Skia. Credit to Sweetchip
[$1000][693974] Medium CVE-2017-5064: Use after free in Blink. Credit to Wadih Matar
[$500][704560] Medium CVE-2017-5065: Incorrect UI in Blink. Credit to Khalil Zhani
[$500][690821] Medium CVE-2017-5066: Incorrect signature handing in Networking. Credit to chenchu
[$500][648117] Medium CVE-2017-5067: URL spoofing in Omnibox. Credit to Khalil Zhani
[$N/A][691726] Low CVE-2017-5069: Cross-origin bypass in Blink. Credit to Michael Reizelman
We would also like to thank all security researchers that worked with us during the development cycle to prevent security bugs from ever reaching the stable channel.
As usual, our ongoing internal security work was responsible for a wide range of fixes:
[713205] Various fixes from internal audits, fuzzing and other initiatives
Many of our security bugs are detected using AddressSanitizer, MemorySanitizer, Control Flow Integrity, or libFuzzer.
Interested in switching release channels? Find out how. If you find a new issue, please let us know by filing a bug. The community help forum is also a great place to reach out for help or learn about common issues.
Krishna Govind
Google Chrome : https://www.google.com/chrome/browser/desktop/ Get a fast, free web browser
One browser for your computer, phone and tablet
Download Chrome
For Windows 10/8.1/8/7 64-bit
Download Chrome for another platform Browse faster Search instantly
Search and navigate from the same box. Choose from results and suggestions that appear as you type, including your recent searches and visited websites, so you can get to what you want in a snap. Search from the omnibox
Type less
Tired of filling out web forms with the same information time and time again? Autofill lets you complete forms with just one click. And it works across devices too — so you can skip all that small-screen typing. Start using Autofill
Pick up where you left off
Chrome brings your open tabs, bookmarks and recent searches from your computer to your phone or tablet, and vice versa. That way you have your web on all of your devices. Just sign in on your other devices to start syncing. Learn more
Make Chrome yours
Browse just the way you'd like with Chrome themes, apps and extentions. Get straight to your favorite web destinations with bookmarks and start pages. Once you've set up Chrome, your customizations will be kept in sync across all of your devices. Start customizing
https://www.virustotal.com/en/file/49fb0...492629245/ SHA256: 49fb0c816d80889422a5806df5e19ac6f069826484d5608773cde41f2ffb150d
File name: ChromeSetup.exe
Detection ratio: 0 / 60
Analysis date: 2017-04-19 19:14:05 UTC ( 11 minutes ago ) Copyright 2007-2010 Google Inc.
Product Google Update
Original name GoogleUpdateSetup.exe
Internal name Google Update Setup
File version 1.3.32.7
Description Google Update Setup
Signature verification Signed file, verified signature
Signing date 3:46 AM 12/8/2016
Signers
[+] Google Inc
[+] VeriSign Class 3 Code Signing 2010 CA
[+] VeriSign
Counter signers
[+] COMODO SHA-1 Time Stamping Signer
[+] USERTrust (Code Signing) VirusTotal metadata
First submission 2017-04-19 19:14:05 UTC ( 11 minutes ago )
Last submission 2017-04-19 19:14:05 UTC ( 11 minutes ago )
File names Google Update Setup
GoogleUpdateSetup.exe
ChromeSetup.exe