Google Chrome's Dev channel has been updated to version 1.0.154.42. This release fixes a few minor bugs, and updates Gears to 0.5.8.0 to fix an occasional crash in some sites with offline applications enabled.
Gears Cross-Origin Worker VulnerabilityCVE: CVE-2008-5258A vulnerability in Gears could allow an attacker to run code in the context of a site that serves user-controlled files. To exploit this, an attacker needs to upload a malicious file to the victim's site and convince the user to allow the attacker's site to use Gears.Severity: High. Even though this requires convincing users to allow a third-party site to use Gears, it could allow data theft and cross-site scripting on sites hosting user-created content, even those that do not use Gears.Credit: Thanks to Yair Amit, Senior Security Researcher, IBM Rational Application Security Research Team for responsibly reporting the issue to Google.
Use the 'Customize and control Google Chrome' (wrench) menu to open the Bookmark manager. You can search bookmarks, create folders, and drag and drop bookmarks to new locations. The Bookmark Manager's Tools menu lets you export or import bookmarks.
We grouped together all of the configuration options for features that might send data to another service. Open the wrench menu, click Options, and select the Under the Hood tab.
The pop-up blocker formerly just minimized pop-up windows to the lower right corner of the browser window, create one 'constrained' window for each pop-up. Now, Google Chrome displays one small notification in the corner that shows the number of blocked pop-ups. A menu on the notification lets you open a specific pop-up, if needed.
Severity: Moderate. If a user could be enticed to open a downloaded HTML file, this flaw could be exploited to send arbitrary files to an attacker.[Originally fixed in 154.18]