Google has released the new version of its Chrome browser, version 78.
Chrome Browser 78 is available for: Windows, macOS, Linux, Android, ChromeOS, and iOS.
The new version comes with many improvements, fast performance , and many fixes to address security.
What are the new features offered by version 78?
- New Menu
- Password Checkup Extension
- DNS over HTTPS tests
- Dark Mode, which works on all sites
- Tab Hover Cards
Password Checkup
The password checker extension helps users understand whether their passwords are secure or if they have been compromised and leaked online.
DNS Over HTTPS (DoH)
This feature aims to enhance security by bringing the benefits of HTTPS to DNS. If a user connects to a public WiFi, DoH will prevent other WiFi users from seeing the sites the user visits. It can also prevent various spoofing or pharming attacks.
Tab Hover Cards
This feature is very useful for users who open many tabs. It essentially provides information about the details of each tab when users hover over it.
XSS Auditor
The new version of the Chrome browser no longer has the XSS Auditor.
How can you install Chrome Browser version 78?
The installation process is simple. You need to follow these steps: Settings – Help – About Google Chrome.
It will automatically check for new updates and then install them. Alternatively, you can download the version from google.com/chrome.
One of the most important elements of Chrome Browser 78 is that it fixes 37 security bugs
The researchers who discovered the bugs received a total reward of $58,000. Some of the vulnerabilities fixed in the new version are:
- CVE-2019-13699: Critical Use-after-free vulnerability in multimedia. Discovered by Man Yue Mo of Semmle Security Research Team on September 6, 2019 (reward: $20,000).
- CVE-2019-13700: Critical Buffer overrun vulnerability in Blink. Discovered by the same researcher on August 28, 2019 ($15,000 reward).
- CVE-2019-13701: Critical URL spoof vulnerability in navigation. Discovered by David Erceg on August 27, 2019 (reward: $1,000).
- CVE-2019-13702: Administrator privilege escalation in Installer. Discovered by Phillip Langlois and Edward Torkington on August 6, 2019 (reward: $5,000).
- CVE-2019-13703: URL bar spoofing. Discovered by Khalil Zhani on August 12, 2019 (reward: $3,000).
- CVE-2019-13704: CSP bypass. Reported by Jun Kokatsu on September 5, 2019 (reward: $3,000).
- CVE-2019-13705: Extension permission bypass. Reported by Luan Herrera on July 30, 2019 (reward: $2,000).
- CVE-2019-13706: Out-of-bounds read in PDFium. Reported by pdknsk on September 5, 2019 (reward: $2,000).
- CVE-2019-13707: File Saving Issues. Reported by Andrea Palazzo on July 1, 2019 (Bonus: $1,000).
- CVE-2019-13708: HTTP Authentication Error. Reported by Khalil Zhani on February 13, 2019 (Bounty: $1,000)
- CVE-2019-13709: File protection bypass. Reported by Zhong Zhaochen on September 18, 2019 (reward: $1,000).
- CVE-2019-13710: File protection bypass. Reported by bernardo.mrod on August 18, 2017 (reward: $500).
- CVE-2019-13711: Information disclosure. Reported by David Erceg on July 20, 2019 (reward: $500).
- CVE-2019-15903: Buffer overflow. Reported by Sebastian Pipping on September 16, 2019 (reward: $500).
- CVE-2019-13713: Data Leak. Reported by David Erceg on August 13, 2019 (reward: unknown).
- CVE-2019-13714: CSS injection. Reported by Jun Kokatsu, July 10, 2019 (Bounty: $2,000).
- CVE-2019-13715: Addressing error. Reported by xisigr of Tencent on August 31, 2019 (reward: $500).
- CVE-2019-13716: Service worker state error. Reported by Barron Hagerman on September 19, 2019 (reward: $500).
- CVE-2019-13718: IDN spoof. Reported by Khalil Zhani July 20, 2018 (reward: unknown).
