谷歌Chrome v77.0.3865.75正式版發布
谷歌瀏覽器Google Chrome穩定版迎來v77首個版本發布,詳細版本號為v77.0.3865.75,上一個正式版v76.0.3809.132發佈於8月27日,時隔15天Google又發布了新版Chrome瀏覽器,本次升級主要是更新了安全修復和穩定性改進及用戶體驗。
谷歌瀏覽器v76正式版隱藏了瀏覽器地址欄中的http/https和www前綴標記,默認在所有網站上阻止Adobe Flash,用戶可以重新啟用Flash,但只能在單擊到播放模式下使用Flash,同時還會出現一個警告,即Chrome在2020年12月之後將不支持Flash播放器。Adobe也將從2021年起停止支持Flash,所以這個更改是相當明智的。
谷歌瀏覽器v75正式版主要為桌面和網頁開發者引入了幾項新功能和軟件增強。其中在“隱私和安全”設置中新增了用於管理安全密鑰的選項,並支持Scroll Snap Stop來改進手勢導航。
谷歌瀏覽器v74正式版增加了兩個關鍵功能:對網頁和操作系統級集成的減速支持瀏覽器將獲得Windows 10的原生黑暗模式。這比集成瀏覽器外殼更深入,如果從相應PC的Windows操作系統中的應用程序樣式中選擇暗黑模式,瀏覽器現在將自動適應它。
Chrome穩定版已經更新到v77.0.3865.75
安全修復程序和獎勵
更新包括52項安全修復
[$TBD][999311] Critical CVE-2019-5870: Use-after-free in media. Reported by Guang Gong of Alpha Team, Qihoo 360 on 2019-08-29
[$7500][990570] High CVE-2019-5871 : Heap overflow in Skia. Reported by Anonymous on 2019-08-03
[$3000][981492] High CVE-2019-5872: Use-after-free in Mojo. Reported by Zhe Jin(金哲),Luyao Liu(劉路遙) from Chengdu Security Response
Center of Qihoo 360 Technology Co. Ltd on 2019-07-05
[$3000][989497] High CVE-2019-5873: URL bar spoofing on iOS. Reported by Khalil Zhani on 2019-07-31
[ $3000][989797] High CVE-2019-5874: External URIs may trigger other browsers. Reported by James Lee (@Windowsrcer) on 2019-08-01
[$2000][979443] High CVE-2019-5875: URL bar spoof via download redirect. Reported by Khalil Zhani on 2019-06-28
[$TBD][997190] High CVE-2019-5876: Use-after-free in media. Reported by Man Yue Mo of Semmle Security Research Team on 2019-08-23
[$TBD][999310] High CVE-2019- 5877: Out-of-bounds access in V8. Reported by Guang Gong of Alpha Team, Qihoo 360 on 2019-08-29
[$TBD][1000217] High CVE-2019-5878: Use-after-free in V8. Reported by Guang Gong of Alpha Team, Qihoo 360 on 2019-09-03
[$3000][986043] Medium CVE-2019-5879: Extension can bypass same origin policy. Reported by Jinseo Kim on 2019-07-20
[$2000][831725 ] Medium CVE-2019-5880: SameSite cookie bypass. Reported by Jun Kokatsu (@shhnjk) on 2018-04-11
[$2000][980816] Medium CVE-2019-5881: Arbitrary read in SwiftShader. Reported by Zhe Jin(金哲),Luyao Liu(劉路遙) from Chengdu Security Response
Center of Qihoo 360 Technology Co. Ltd on 2019-07-03
[$1000][868846] Medium CVE-2019-13659: URL spoof. Reported by Lnyas Zhang on 2018-07-30
[$1000][882363] Medium CVE-2019 -13660: Full screen notification overlap. Reported by Wenxu Wu (@ma7h1as) of Tencent Security Xuanwu Lab on 2018-09-10
[$1000][882812] Medium CVE-2019-13661: Full screen notification spoof. Reported by Wenxu Wu ( @ma7h1as) of Tencent Security Xuanwu Lab on 2018-09-11
[$1000][967780] Medium CVE-2019-13662: CSP bypass. Reported by David Erceg on 2019-05-28
[$500][863661] Medium CVE-2019 -13663: IDN spoof. Reported by Lnyas Zhang on 2018-07-14
[$500][915538] Medium CVE-2019-13664: CSRF bypass. Reported by thomas “zemnmez” shadwell on 2018-12-16
[$500][959640] Medium CVE-2019-13665: Multiple file download protection bypass. Reported by Jun Kokatsu, Microsoft Browser Vulnerability Research on 2019-05-05
[$500][960305] Medium CVE-2019-13666: Side channel using storage size estimate. Reported by Tom Van Goethem from imec-DistriNet, KU Leuven on 2019-05-07
[$500][973056] Medium CVE-2019-13667: URI bar spoof when using external app URIs. Reported by Khalil Zhani on 2019 -06-11
[$500][986393] Medium CVE-2019-13668: Global window leak via console. Reported by David Erceg on 2019-07-22
[$N/A][968451] Medium CVE-2019-13669: HTTP authentication spoof. Reported by Khalil Zhani on 2019-05-30
[$N/A][980891] Medium CVE-2019-13670: V8 memory corruption in regex. Reported by Guang Gong of Alpha Team, Qihoo 360 on 2019-07- 03
[$TBD][696454] Medium CVE-2019-13671: Dialog box fails to show origin. Reported by xisigr of Tencent’s Xuanwu Lab on 2017-02-27
[$TBD][997925] Medium CVE-2019-13673: Cross- origin information leak using devtools. Reported by David Erceg on 2019-08-26
[$500][896533] Low CVE-2019-13674: IDN spoofing. Reported by Khalil Zhani on 2018-10-18
[$500][929578] Low CVE -2019-13675: Extensions can be disabled by trailing slash. Reported by Jun Kokatsu, Microsoft Browser Vulnerability Research on 2019-02-07
[$TBD][875178] Low CVE-2019-13676: Google URI shown for certificate warning. Reported by Wenxu Wu (@ma7h1as) of Tencent Security Xuanwu Lab on 2018-08-17
[$TBD][939108] Low CVE-2019-13677: Chrome web store origin needs to be isolated. Reported by Jun Kokatsu, Microsoft Browser Vulnerability Research on 2019-03-06
[$TBD][946633] Low CVE-2019- 13678: Download dialog spoofing. Reported by Ronni Skansing on 2019-03-27
[$TBD][968914] Low CVE-2019-13679: User gesture needed for printing. Reported by Conrad Irwin, Superhuman on 2019-05-31
[$ TBD][969684] Low CVE-2019-13680: IP address spoofing to servers. Reported by Thijs Alkemade from Computest on 2019-06-03
[$TBD][970378] Low CVE-2019-13681: Bypass on download restrictions. Reported by David Erceg on 2019-06-04
[$TBD][971917] Low CVE-2019-13682: Site isolation bypass. Reported by Jun Kokatsu, Microsoft Browser Vulnerability Research on 2019-06-07
[$TBD][987502] Low CVE-2019-13683: Exceptions leaked by devtools. Reported by David Erceg on 2019-07-25
[1002279] Various fixes from internal audits, fuzzing and other initiatives
Google Chrome 穩定版離線安裝包官方本地下載地址:
Google Chrome v77.0.3865.75無更新功能版64位
SHA1:494E20012995ADC644127F8A827ABB986C7A522D
SHA256:6338AD7003F55DEA18EAE8F31E04F0346189FCA3104DF6A0C7199DADF862BE32
http://dl.google.com/release2/chrome/DwRvDRtUAD LG WiTxTGOE6A_77.0.3865.75/77.0.3865.75_chrome_installer.exe
https:/ /dl.google.com/release2/chrome/DwRvDRtUADLGWiTxTGOE6A_77.0.3865.75/77.0.3865.75_chrome_installer.exe
http://www.google.com/dl/release2/chrome/DwRvDRtUADLGWiTxTGOE6A_77.0.3865.75/77.0.3865.75_chrome_installer. exe
https://www.google.com/dl/release2/chrome/DwRvDRtUADLGWiTxTGOE6A_77.0.3865.75/77.0.3865.75_chrome_installer.exe
http://redirector.gvt1.com/edgedl/release2/chrome/DwRvDRtUADLGWiTxTGOE6A_77.0.3865.75 /77.0.3865.75_chrome_installer.exe
https://redirector.gvt1.com/edgedl/release2/chrome/DwRvDRtUADLGWiTxTGOE6A_77.0.3865.75/77.0.3865.75_chrome_installer.exe
Google Chrome v77.0.3865.75無更新功能版32位
SHA1:D850588A450F223188C1BC5B8A74D4B1B2588BCD
SHA256:E255E921C0E3681A0103905AA9256ECCD19E6396CDF7531663BA4CB75A414723
http://dl.google.com/release2/chrome/ALZQVEfNiq-Fl8VbcSwmquI_77.0.3865.75/77.0.3865.75_chrome_installer.exe
https:/ /dl.google.com/release2/chrome/ALZQVEfNiq-Fl8VbcSwmquI_77.0.3865.75/77.0.3865.75_chrome_installer.exe
http://www.google.com/dl/release2/chrome/ALZQVEfNiq-Fl8VbcSwmquI_77.0.3865.75/77.0 .3865.75_chrome_installer.exe
https://www.google.com/dl/release2/chrome/ALZQVEfNiq-Fl8VbcSwmquI_77.0.3865.75/77.0.3865.75_chrome_installer.exe
http://redirector.gvt1.com/edgedl/release2/chrome /ALZQVEfNiq-Fl8VbcSwmquI_77.0.3865.75/77.0.3865.75_chrome_installer.exe
https://redirector.gvt1.com/edgedl/release2/chrome/ALZQVEfNiq-Fl8VbcSwmquI_77.0.3865.75/77.0.3865.75_chrome_installer.exe
Google Chrome v77.0.3865.75 Mac版
SHA1:3E84D907E2D3DB36CB817C7A5A74A17433DE86C2
SHA256:E6C9AB31CE839FFA9CBA9E31D7FA1E9B5771DE2CDAA1864005B47E3AC54D3573
http://dl.google.com/release2/chrome/AIBGy5UGN05JhULHdKodKU0_77.0.3865.75/GoogleChrome-77.0.3865.75.dmg
https://dl.google. com/release2/chrome/AIBGy5UGN05JhULHdKodKU0_77.0.3865.75/GoogleChrome-77.0.3865.75.dmg
http://www.google.com/dl/release2/chrome/AIBGy5UGN05JhULHdKodKU0_77.0.3865.75/GoogleChrome-77.0.3865.75.dmg
https: //www.google.com/dl/release2/chrome/AIBGy5UGN05JhULHdKodKU0_77.0.3865.75/GoogleChrome-77.0.3865.75.dmg
http://redirector.gvt1.com/edgedl/release2/chrome/AIBGy5UGN05JhULHdKodKU0_77.0.3865.75/GoogleChrome -77.0.3865.75.dmg
https://redirector.gvt1.com/edgedl/release2/chrome/AIBGy5UGN05JhULHdKodKU0_77.0.3865.75/GoogleChrome-77.0.3865.75.dmg
Google Chrome官方帶更新功能版網盤:
https://www.lanzous.com/b138066