Google Chrome v66.0.3359.117 正式版发布

谷歌浏览器Google Chrome稳定版迎来v66正式版第一个版本发布,详细版本号为v66.0.3359.117,本次更新主要包括以下内容:首先是新的媒体播放行为控制。在默认情况下,自动播放的内容会被默认静音(连同其它权限制约);其次是密码导出功能,用户可以在“托管密码”(Managed Passwords)里下载 .csv 格式的文件。然后是“隔离试验”,其通过“将不同网站页面放到不同的进程中运行”来提升安全性(每个进程都被阻止从其它站点接收敏感数据),有助于降低“幽灵”(Spectre)芯片漏洞带来的风险。此外还包含62项安全修复及稳定性改进。

值得一提的是,Chrome 66 现已不再信任由赛门铁克传统 PKI 签发的网站证书。

Chrome 65版本开始扩展页面全面启用Material Design设计,同时为web开发者新增了两个全新API,分别是CSS Paint API和ServerTiming API。

官方更新日志:
[$TBD][826626] Critical CVE-2018-6085: Use after free in Disk Cache. Reported by Ned Williamson on 2018-03-28
[$TBD][827492] Critical CVE-2018-6086: Use after free in Disk Cache. Reported by Ned Williamson on 2018-03-30
[$7500][813876] High CVE-2018-6087: Use after free in WebAssembly. Reported by Anonymous on 2018-02-20
[$5000][822091] High CVE-2018-6088: Use after free in PDFium. Reported by Anonymous on 2018-03-15
[$4500][808838] High CVE-2018-6089: Same origin policy bypass in Service Worker. Reported by Rob Wu on 2018-02-04
[$3000][820913] High CVE-2018-6090: Heap buffer overflow in Skia. Reported by ZhanJia Song on 2018-03-12
[$500][771933] High CVE-2018-6091: Incorrect handling of plug-ins by Service Worker. Reported by Jun Kokatsu (@shhnjk) on 2017-10-05
[$N/A][819869] High CVE-2018-6092: Integer overflow in WebAssembly. Reported by Natalie Silvanovich of Google Project Zero on 2018-03-08
[$4000][780435] Medium CVE-2018-6093: Same origin bypass in Service Worker. Reported by Jun Kokatsu (@shhnjk) on 2017-11-01
[$2000][633030] Medium CVE-2018-6094: Exploit hardening regression in Oilpan. Reported by Chris Rohlf on 2016-08-01
[$2000][637098] Medium CVE-2018-6095: Lack of meaningful user interaction requirement before file upload. Reported by Abdulrahman Alqabandi (@qab) on 2016-08-11
[$1000][776418] Medium CVE-2018-6096: Fullscreen UI spoof. Reported by WenXu Wu of Tencent’s Xuanwu Lab on 2017-10-19
[$1000][806162] Medium CVE-2018-6097: Fullscreen UI spoof. Reported by xisigr of Tencent’s Xuanwu Lab on 2018-01-26
[$500][798892] Medium CVE-2018-6098: URL spoof in Omnibox. Reported by Khalil Zhani on 2018-01-03
[$500][808825] Medium CVE-2018-6099: CORS bypass in ServiceWorker. Reported by Jun Kokatsu (@shhnjk) on 2018-02-03
[$500][811117] Medium CVE-2018-6100: URL spoof in Omnibox. Reported by Lnyas Zhang on 2018-02-11
[$500][813540] Medium CVE-2018-6101: Insufficient protection of remote debugging prototol in DevTools . Reported by Rob Wu on 2018-02-19
[$500][813814] Medium CVE-2018-6102: URL spoof in Omnibox. Reported by Khalil Zhani on 2018-02-20
[$500][816033] Medium CVE-2018-6103: UI spoof in Permissions. Reported by Khalil Zhani on 2018-02-24
[$500][820068] Medium CVE-2018-6104: URL spoof in Omnibox. Reported by Khalil Zhani on 2018-03-08
[$N/A][803571] Medium CVE-2018-6105: URL spoof in Omnibox. Reported by Khalil Zhani on 2018-01-18
[$N/A][805729] Medium CVE-2018-6106: Incorrect handling of promises in V8. Reported by lokihardt of Google Project Zero on 2018-01-25
[$N/A][808316] Medium CVE-2018-6107: URL spoof in Omnibox. Reported by Khalil Zhani on 2018-02-02
[$N/A][816769] Medium CVE-2018-6108: URL spoof in Omnibox. Reported by Khalil Zhani on 2018-02-27
[$N/A][710190] Low CVE-2018-6109: Incorrect handling of files by FileAPI. Reported by Dominik Weber (@DoWeb_) on 2017-04-10
[$N/A][777737] Low CVE-2018-6110: Incorrect handling of plaintext files via file:// . Reported by Wenxiang Qian (aka blastxiang) on 2017-10-24
[$N/A][780694] Low CVE-2018-6111: Heap-use-after-free in DevTools. Reported by Khalil Zhani on 2017-11-02
[$N/A][798096] Low CVE-2018-6112: Incorrect URL handling in DevTools. Reported by Rob Wu on 2017-12-29
[$N/A][805900] Low CVE-2018-6113: URL spoof in Navigation. Reported by Khalil Zhani on 2018-01-25
[$N/A][811691] Low CVE-2018-6114: CSP bypass. Reported by Lnyas Zhang on 2018-02-13
[$TBD][819809] Low CVE-2018-6115: SmartScreen bypass in downloads. Reported by James Feher on 2018-03-07
[$N/A][822266] Low CVE-2018-6116: Incorrect low memory handling in WebAssembly. Reported by Jin from Chengdu Security Response Center of Qihoo 360 Technology Co. Ltd. on 2018-03-15
[$N/A][822465] Low CVE-2018-6117: Confusing autofill settings. Reported by Spencer Dailey on 2018-03-15
[$N/A][822424] Low CVE-2018-6084: Incorrect use of Distributed Objects in Google Software Updater on MacOS. Reported by Ian Beer of Google Project Zero on 2018-03-15
[833889] Various fixes from internal audits, fuzzing and other initiatives

Google Chrome 离线安装包 官方下载地址:

Google Chrome v66.0.3359.117 无在线更新离线安装包 32位:https://redirector.gvt1.com/edgedl/release2/chrome/MtkyEb_CNQE_66.0.3359.117/66.0.3359.117_chrome_installer.exe

Google Chrome v66.0.3359.117无在线更新离线安装包 64位:https://redirector.gvt1.com/edgedl/release2/chrome/Qystcf3MOD8_66.0.3359.117/66.0.3359.117_chrome_installer.exe

发表评论

6 条评论

  1. 匿名 安卓手机 2018-06-25 21:00
    #6楼

    :evil: :wink: :sad: :lol: :cry: :wink: :cool: 哈哈

    支持[0]反对[0]
  2. 匿名 iPhone 2018-06-20 16:53
    #5楼

    :cry: 哈哈

    支持[0]反对[0]
  3. 匿名 Windows 10 x64 Chrome 63.0.3239.26 2018-04-20 15:39
    #4楼

    不接地气啊

    支持[1]反对[0]
  4. 匿名 Windows XP Chrome 49.0.2623.112 2018-04-19 14:31
    #地板

    XP 49路过~

    支持[0]反对[0]
  5. 匿名 Windows 10 x64 Internet Explorer 11.0 2018-04-19 10:42
    #板凳

    Google Chrome最爱浏览器,没有之一

    支持[0]反对[0]
  6. 匿名 Windows 10 x64 Chrome 65.0.3325.181 2018-04-18 14:05
    #沙发

    。。。。放弃治疗了吗?怎么不更新了?

    支持[2]反对[0]