Software Update: Google Chrome 31.0.1650.48

Spread the love

Google has released version 31 of its Chrome web browser. Google Chrome is available in three different versions: stable, beta and dev, and this time the stable version has been updated. No new features have been added in version 31, but a large number of security updates have been made again. The full changelog for this release can be found below.

Stable Channel Update

Chrome has been updated to 31.0.1650.48 for Windows, Mac, Linux and Chrome Frame. Flash Player has been updated to 11.9.900.152, which is included w/ this release.

Security Fixes and Rewards

Note: Access to bug details and links may be kept restricted until a majority of users are updated with a fix. We will also retain restrictions if the bug exists in a third party library that other projects similarly depend on, but haven’t yet fixed. This update includes 25 security fixes. Below, we highlight fixes that were either contributed by external researchers or particularly interesting. Please see the Chromium security page for more information.

  • [268565] Medium CVE-2013-6621: Use after free related to speech input elements.
  • [272786] High CVE-2013-6622: Use after free related to media elements.
  • [282925] High CVE-2013-6623: Read out of bounds in SVG.
  • [290566] High CVE-2013-6624: Use after free related to “id” attribute strings.
  • [295010] High CVE-2013-6625: Use after free in DOM ranges.
  • [295695] Low CVE-2013-6626: Address bar spoofing related to interstitial warnings.
  • [299892] High CVE-2013-6627: Read out of bounds in HTTP parsing.
  • [306959] Medium CVE-2013-6628: Issue with certificates not being checked during TLS renegotiation.

We would also like to thank miaubiz and Atte Kettunen of OUSPG for working with us during the development cycle to prevent security bugs from ever reaching the stable channel. As usual, our ongoing internal security work responsible for a wide range of fixes:

  • [315823] Medium-Critical CVE-2013-2931: Various fixes from internal audits, fuzzing and other initiatives.
  • [258723] Medium CVE-2013-6629: Read of uninitialized memory in libjpeg and libjpeg-turbo.
  • [299835] Medium CVE-2013-6630: Read of uninitialized memory in libjpeg-turbo.
  • [296804] High CVE-2013-6631: Use after free in libjingle.

Many of the above bugs were detected using AddressSanitizer.

A full list of changes is available in the SVN log. Interested in switching release channels? Find out how. If you find a new issue, please let us know by filing a bug.

Version number 31.0.1650.48
Release status Final
Operating systems Windows 7, Linux, Windows XP, macOS, Windows Vista, Windows 8
Website google
Download http://www.google.com/chrome/index.html?hl=nl
License type Freeware
You might also like