<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Browsers on Omid Farhang</title><link>https://omid.dev/tags/browsers/</link><description>Recent content in Browsers on Omid Farhang</description><image><title>Omid Farhang</title><url>https://omid.dev/images/bio-photo-150x150.jpg</url><link>https://omid.dev/images/bio-photo-150x150.jpg</link></image><generator>Hugo -- 0.163.3</generator><language>en-US</language><copyright>2026 Omid Farhang | All rights reserved.</copyright><lastBuildDate>Thu, 25 Sep 2014 22:10:46 +0000</lastBuildDate><atom:link href="https://omid.dev/tags/browsers/index.xml" rel="self" type="application/rss+xml"/><atom:link href="https://pubsubhubbub.appspot.com/" rel="hub"/><item><title>What you need to know about BERserk and Mozilla</title><link>https://omid.dev/2014/09/25/need-know-berserk-mozilla/</link><pubDate>Thu, 25 Sep 2014 22:10:46 +0000</pubDate><guid>https://omid.dev/2014/09/25/need-know-berserk-mozilla/</guid><description>&lt;p&gt;The &lt;strong&gt;Intel Security Advanced Threat Research Team&lt;/strong&gt; has discovered a critical signature forgery vulnerability in the &lt;strong&gt;Mozilla Network Security Services (NSS) crypto library&lt;/strong&gt; that could allow malicious parties to set up fraudulent sites masquerading as legitimate businesses and other organizations.&lt;/p&gt;
&lt;p&gt;The Mozilla NSS library, commonly utilized in the &lt;strong&gt;Firefox web browser, can also be found in Thunderbird, Seamonkey, and other Mozilla products.&lt;/strong&gt;  Dubbed &lt;strong&gt;“BERserk”&lt;/strong&gt;, this vulnerability allows for attackers to forge RSA signatures, thereby allowing for the bypass of authentication to websites utilizing SSL/TLS.  Given that certificates can be forged for any domain, this issue raises serious concerns around integrity and confidentiality as we traverse what we perceive to be secure websites.&lt;/p&gt;</description></item><item><title>Chrome 28 with new Blink engine and Rich Notifications</title><link>https://omid.dev/2013/07/10/chrome-28-with-new-blink-engine-and-rich-notifications/</link><pubDate>Wed, 10 Jul 2013 13:31:59 +0000</pubDate><guid>https://omid.dev/2013/07/10/chrome-28-with-new-blink-engine-and-rich-notifications/</guid><description>&lt;p&gt;Cross-posted from H-Online:&lt;/p&gt;
&lt;p&gt;&lt;a href="https://omid.dev/images/2013/05/new-chrome-logo.png"&gt;&lt;img loading="lazy" src="https://omid.dev/images/2013/05/new-chrome-logo.png" alt="new-chrome-logo" /&gt;
&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;Google &lt;a href="http://googlechromereleases.blogspot.co.uk/2013/07/stable-channel-update.html"&gt;has released&lt;/a&gt; the stable version 28 of its Chrome browser. It is the first version to use the new &lt;a href="http://www.chromium.org/blink"&gt;Blink engine&lt;/a&gt; for rendering web pages and it appears that the new engine will allow web pages to be loaded about ten per cent faster. The developers say that the increased speed is also thanks to the new &lt;a href="https://groups.google.com/a/chromium.org/forum/#%21topic/chromium-dev/hBUVtg7gacE"&gt;threaded HTML parser&lt;/a&gt;, which frees up the JavaScript thread, allowing DOM content to be displayed faster. The HTML parser also takes fewer breaks, which is said to result in time savings of up to 40 per cent. Another contributor to the faster working speed is the optimized &lt;a href="https://code.google.com/p/v8/"&gt;V8&lt;/a&gt; JavaScript engine.&lt;/p&gt;</description></item><item><title>Internet Explorer 8 0-Day Update CVE-2013-1347</title><link>https://omid.dev/2013/05/06/internet-explorer-8-0-day-update-cve-2013-1347/</link><pubDate>Mon, 06 May 2013 15:30:02 +0000</pubDate><guid>https://omid.dev/2013/05/06/internet-explorer-8-0-day-update-cve-2013-1347/</guid><description>&lt;p&gt;&lt;img loading="lazy" src="https://omid.dev/images/2013/05/internetexplorer9logo.png" alt="" /&gt;
&lt;/p&gt;
&lt;p&gt;Microsoft has confirmed a bug in Internet Explorer 8, CVE-2013-1347, which exposes user machines to remote code execution.&lt;/p&gt;
&lt;p&gt;In an &lt;a href="http://technet.microsoft.com/en-us/security/advisory/2847140"&gt;advisory&lt;/a&gt;, Microsoft says the vulnerability “exists in the way that Internet Explorer [accesses] an object in memory that has been deleted or has not been properly allocated.”&lt;/p&gt;
&lt;p&gt;That, in turn, opens the door to memory corruption and remote code execution in the current user context.&lt;/p&gt;
&lt;p&gt;According to this &lt;a href="http://eromang.zataz.com/2013/05/05/cve-2013-1347-microsoft-internet-explorer-8-vulnerability-metasploit-demo/"&gt;blog post&lt;/a&gt; by Eric Roman: “A use-after-free condition occurs when a CGenericElement object is freed, but a reference is kept on the document and used again during rendering, an invalid memory that’s controllable is used, and allows arbitrary code execution under the context of the user.”&lt;/p&gt;</description></item><item><title>Internet Explorer 10 for Windows 7 [Download Links]</title><link>https://omid.dev/2013/02/26/internet-explorer-10-for-windows-7-download-links/</link><pubDate>Tue, 26 Feb 2013 17:47:00 +0000</pubDate><guid>https://omid.dev/2013/02/26/internet-explorer-10-for-windows-7-download-links/</guid><description>&lt;p&gt;Internet Explorer 10 is available worldwide in 95 languages for &lt;a href="http://windows.microsoft.com/ie"&gt;download today&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;Read more in IE Blog: &lt;a href="http://blogs.msdn.com/b/ie/archive/2013/02/26/ie10-for-windows-7-globally-available-for-consumers-and-businesses.aspx" title="http://blogs.msdn.com/b/ie/archive/2013/02/26/ie10-for-windows-7-globally-available-for-consumers-and-businesses.aspx"&gt;http://blogs.msdn.com/b/ie/archive/2013/02/26/ie10-for-windows-7-globally-available-for-consumers-and-businesses.aspx&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href="http://lh3.ggpht.com/-0Zw4c__hQg0/USzuF3r_QYI/AAAAAAAAH2E/hCpB-sg--UA/s1600-h/ie10_start%25255B4%25255D.png"&gt;&lt;img loading="lazy" src="http://lh4.ggpht.com/-HyOGfB5SeNs/USzuKSS2pxI/AAAAAAAAH2M/Qaip3m-Hmdc/ie10_start_thumb%25255B2%25255D.png?imgmax=800" alt="ie10_start" title="ie10_start" /&gt;
&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;Download Links:&lt;/p&gt;
&lt;p&gt;x86: &lt;a href="http://www.microsoft.com/en-us/download/details.aspx?id=36808"&gt;http://www.microsoft.com/en-us/download/details.aspx?id=36808&lt;/a&gt;&lt;br&gt;
x64: &lt;a href="http://www.microsoft.com/en-us/download/details.aspx?id=36806"&gt;http://www.microsoft.com/en-us/download/details.aspx?id=36806&lt;/a&gt;&lt;br&gt;
Other (Non-English) Languages: &lt;a href="http://windows.microsoft.com/en-us/internet-explorer/downloads/ie-10/worldwide-languages"&gt;http://windows.microsoft.com/en-us/internet-explorer/downloads/ie-10/worldwide-languages&lt;/a&gt;&lt;/p&gt;</description></item><item><title>Opera Switches to WebKit and Chromium</title><link>https://omid.dev/2013/02/13/opera-switches-to-webkit-and-chromium/</link><pubDate>Wed, 13 Feb 2013 22:38:00 +0000</pubDate><guid>https://omid.dev/2013/02/13/opera-switches-to-webkit-and-chromium/</guid><description>&lt;p&gt;After many years of dealing with site compatibility issues, Opera found &lt;a href="http://my.opera.com/haavard/blog/2013/02/13/webkit"&gt;the solution&lt;/a&gt;: it will switch from its proprietary rendering engine (Presto) to WebKit and &lt;a href="http://my.opera.com/ODIN/blog/300-million-users-and-move-to-webkit"&gt;will be powered by Chrome&amp;rsquo;s open source version, Chromium&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;“Presto is a great little engine. It&amp;rsquo;s small, fast, flexible and standards compliant while at the same time handling real-world web sites. It has allowed us to port Opera to just about any platform you can imagine. (…) It was always a goal to be compatible with the real web while also supporting and promoting open standards. That turns out to be a bit of a challenge when you are faced with a web that is not as open as one might have wanted. Add to that the fact that it is constantly changing and that you don&amp;rsquo;t get site compatibility for free (which some browsers are fortunate enough to do), and it ends up taking up a lot of resources – resources that could have been spent on innovation and polish instead,” &lt;a href="http://my.opera.com/haavard/blog/2013/02/13/webkit"&gt;explains an Opera employee&lt;/a&gt;.&lt;/p&gt;</description></item><item><title>Google updates all Chrome editions</title><link>https://omid.dev/2012/11/29/google-updates-all-chrome-editions/</link><pubDate>Thu, 29 Nov 2012 20:48:00 +0000</pubDate><guid>https://omid.dev/2012/11/29/google-updates-all-chrome-editions/</guid><description>&lt;p&gt;&lt;img loading="lazy" src="http://lh4.ggpht.com/-jf_RJKSlvmw/ULfDIl4eitI/AAAAAAAAHoY/ok_C5icwWyQ/s1600-h/new-chrome-logo%25255B2%25255D.png" alt="new-chrome-logo" /&gt;
&lt;/p&gt;
&lt;p&gt;h-online: Google has updated the Stable, Beta and Developer Channels of the desktop version of its Chrome browser with a number of bug fixes and improvements. The Stable Channel update closes seven security vulnerabilities, three of them rated High, and includes bug fixes. New stable Chrome versions for iOS and Android have also been released and include minor improvements. The iOS version of the browser now supports Apple&amp;rsquo;s Passbook application.&lt;/p&gt;</description></item><item><title>Internet Explorer security hole: Use other browser</title><link>https://omid.dev/2012/09/18/internet-explorer-security-hole-use-other-browser/</link><pubDate>Tue, 18 Sep 2012 16:22:00 +0000</pubDate><guid>https://omid.dev/2012/09/18/internet-explorer-security-hole-use-other-browser/</guid><description>&lt;p&gt;&lt;strong&gt;TheTelegraph: Internet Explorer users might want to consider upgrading or switching to another browser after a massive security hole was discovered in Windows&amp;rsquo; native web browser.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;img loading="lazy" src="http://lh3.ggpht.com/-0Bv3ALH0CoQ/UFiYtKVSU0I/AAAAAAAAHc8/1JyUQDPOw20/s1600-h/internetexplorer9logo%25255B3%25255D.png" alt="internetexplorer9logo" /&gt;
&lt;/p&gt;
&lt;p&gt;According to security forum, Rapid7 , Internet Explorer 7, 8 and 9 operating on Windows XP, Vista and Seven contains what is known as a “zero day exploit” which allows attackers to gain access to your personal data while you browse.&lt;/p&gt;
&lt;p&gt;The forum claimed the exploit would give cyber criminals “the same privileges as the current user”.&lt;/p&gt;</description></item><item><title>Download Firefox 15 and Thunderbird 15!</title><link>https://omid.dev/2012/08/28/download-firefox-15-and-thunderbird-15/</link><pubDate>Tue, 28 Aug 2012 16:55:00 +0000</pubDate><guid>https://omid.dev/2012/08/28/download-firefox-15-and-thunderbird-15/</guid><description>&lt;p&gt;Cross-copied from &lt;a href="http://betanews.com/2012/08/28/download-firefox-15-and-thunderbird-15-now/"&gt;BetaNews&lt;/a&gt;:&lt;/p&gt;
&lt;p&gt;&lt;img loading="lazy" src="http://lh4.ggpht.com/-ZoPErUioMCk/UDzwx4iIvGI/AAAAAAAAHQU/GW5FEZuXKq4/s1600-h/Firefox-15%25255B5%25255D.jpg" alt="Firefox-15" /&gt;
&lt;/p&gt;
&lt;p&gt;Mozilla has quietly placed major new versions of its open-source, cross-platform web browser and email client onto its download servers ahead of an official release.&lt;/p&gt;
&lt;p&gt;&lt;a href="http://www.downloadcrew.com/article/24333-firefox"&gt;Firefox 15 FINAL&lt;/a&gt; benefits largely from behind-the-scenes performance tweaks, while &lt;a href="http://www.downloadcrew.com/article/24287-mozilla_thunderbird"&gt;Thunderbird 15 FINAL&lt;/a&gt; introduces a few new features, including a new curvy user interface.&lt;/p&gt;
&lt;p&gt;Firefox 15 FINAL’s most notable changes are performance-based. There’s faster startup on Windows PCs, plus incremental garbage collection and better management of plugins to prevent memory leaks. Other performance improvements surround WebGL enhancements.&lt;/p&gt;</description></item><item><title>IE 9.0.9 Available via Windows Update</title><link>https://omid.dev/2012/08/16/ie-9-0-9-available-via-windows-update/</link><pubDate>Thu, 16 Aug 2012 10:43:00 +0000</pubDate><guid>https://omid.dev/2012/08/16/ie-9-0-9-available-via-windows-update/</guid><description>&lt;p&gt;MSDN:&lt;/p&gt;
&lt;p&gt;&lt;img loading="lazy" src="http://lh3.ggpht.com/-qAYbwQpCauA/UCzH0B4SFII/AAAAAAAAG-E/k0aqdkRp0xk/s1600-h/internetexplorer9logo%25255B6%25255D.png" alt="internetexplorer9logo" /&gt;
&lt;/p&gt;
&lt;p&gt;The &lt;a href="http://support.microsoft.com/kb/2722913"&gt;&lt;strong&gt;August 2012 Cumulative Security Update for Internet Explorer&lt;/strong&gt;&lt;/a&gt; is now available via &lt;a href="http://go.microsoft.com/fwlink/?LinkID=40747"&gt;&lt;strong&gt;Windows Update&lt;/strong&gt;&lt;/a&gt;. This security update resolves four privately reported vulnerabilities in Internet Explorer. The most severe vulnerabilities could allow remote code execution if a user views a specially crafted Web page using Internet Explorer. An attacker who successfully exploited any of these vulnerabilities could gain the same user rights as the current user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights This security update is rated Critical for Internet Explorer 6, Internet Explorer 7, Internet Explorer 8, and Internet Explorer 9 on Windows clients and Moderate for Internet Explorer 6, Internet Explorer 7, Internet Explorer 8, and Internet Explorer 9 on Windows servers For more information, see the &lt;a href="http://technet.microsoft.com/en-us/security/bulletin/ms12-052"&gt;full bulletin&lt;/a&gt;.&lt;/p&gt;</description></item><item><title>Chrome 20 update fixes high-risk security vulnerabilities</title><link>https://omid.dev/2012/07/13/chrome-20-update-fixes-high-risk-security-vulnerabilities/</link><pubDate>Fri, 13 Jul 2012 10:03:00 +0000</pubDate><guid>https://omid.dev/2012/07/13/chrome-20-update-fixes-high-risk-security-vulnerabilities/</guid><description>&lt;p&gt;&lt;img loading="lazy" src="http://lh5.ggpht.com/-vYl4yEWgrfI/T__rRbCEeDI/AAAAAAAAGbs/tR0q8JAKK-s/s1600-h/Google_Chrome_Logo%25255B2%25255D.png" alt="Google_Chrome_Logo" /&gt;
&lt;/p&gt;
&lt;p&gt;Google has &lt;a href="http://googlechromereleases.blogspot.com/2012/07/stable-channel-update.html"&gt;published a new update&lt;/a&gt; to the stable 20.x branch of Chrome to close a number of security holes in the WebKit-based web browser. Version 20.0.1132.57 of Chrome addresses a total of three vulnerabilities, all of which are rated as “high severity” by the company.&lt;/p&gt;
&lt;p&gt;These include two use-after-free errors in counter handling and in layout height tracking that were discovered by a security researcher by the name of “miaubiz”. As part of its &lt;a href="https://sites.google.com/a/chromium.org/dev/Home/chromium-security"&gt;Chromium Security Vulnerability Rewards program&lt;/a&gt;, Google paid the researcher, who is number three in the company&amp;rsquo;s &lt;a href="http://www.chromium.org/Home/chromium-security/hall-of-fame"&gt;Security Hall of Fame&lt;/a&gt;, $1,000 for discovering and reporting each of the holes. A third high-risk problem related to object access with JavaScript in PDFs has also been corrected. As usual, further details about the vulnerabilities are being withheld until “a majority of users are up-to-date with the fix”. Other changes include stability improvements, and updates to the V8 JavaScript engine and the built-in Flash player plug-in.&lt;/p&gt;</description></item><item><title>Chrome 20 closes 23 security holes</title><link>https://omid.dev/2012/06/27/chrome-20-closes-23-security-holes/</link><pubDate>Wed, 27 Jun 2012 18:08:00 +0000</pubDate><guid>https://omid.dev/2012/06/27/chrome-20-closes-23-security-holes/</guid><description>&lt;p&gt;&lt;img loading="lazy" src="http://lh3.ggpht.com/-5tLk-1Q69IY/T-tFBEJLVMI/AAAAAAAAGYw/qorAPNz8kiM/s1600-h/new-chrome-logo%25255B2%25255D.png" alt="new-chrome-logo" /&gt;
&lt;/p&gt;
&lt;p&gt;Google has closed a total of &lt;a href="http://googlechromereleases.blogspot.com/2012/06/stable-channel-update_26.html"&gt;23 vulnerabilities&lt;/a&gt; with the release of Chrome 20. Of those vulnerabilities, 14 are rated critical, enabling attackers to execute code in the browser&amp;rsquo;s sandbox, among other things. Integer overflow vulnerabilities in the code for processing PDF files and Matroska containers (.mkv) have also been fixed. Chrome 20 also &lt;a href="http://support.google.com/chrome/bin/answer.py?hl=en&amp;amp;answer=108086"&gt;includes&lt;/a&gt; the latest version of Adobe&amp;rsquo;s Flash Player on Linux, using the new cross-platform &lt;a href="https://developers.google.com/native-client/"&gt;Pepper API&lt;/a&gt;. In testing at &lt;strong&gt;The H&lt;/strong&gt;, it was confirmed that the Flash Player support also works on 64-bit Linux systems.&lt;/p&gt;</description></item><item><title>Opera 12 has been released</title><link>https://omid.dev/2012/06/14/opera-12-has-been-released/</link><pubDate>Thu, 14 Jun 2012 11:36:00 +0000</pubDate><guid>https://omid.dev/2012/06/14/opera-12-has-been-released/</guid><description>&lt;p&gt;&lt;img loading="lazy" src="http://lh3.ggpht.com/-_JhpIqYUZwc/T9nFxpyHQbI/AAAAAAAAGRA/wJwgky_aLPA/s1600-h/Opera-logo-new200%25255B2%25255D.png" alt="Opera-logo-new200" /&gt;
&lt;/p&gt;
&lt;p&gt;Norwegian company Opera Software has released &lt;a href="http://www.opera.com/"&gt;Opera 12.00&lt;/a&gt; just a few minutes ago. Opera users who start the browser on their system should see update notifications displayed to them in the next couple of hours. Those who do not want to wait that long can run a manual check for updates with a click on &lt;strong&gt;Opera&lt;/strong&gt; &amp;gt; &lt;strong&gt;Help&lt;/strong&gt; &amp;gt; &lt;strong&gt;Check for Updates&lt;/strong&gt;. The update should then be picked up by the browser and downloaded automatically to the local system.&lt;/p&gt;</description></item><item><title>Firefox 13 Final is available for download [Link]</title><link>https://omid.dev/2012/06/03/firefox-13-final-is-available-for-download-link/</link><pubDate>Sun, 03 Jun 2012 08:49:00 +0000</pubDate><guid>https://omid.dev/2012/06/03/firefox-13-final-is-available-for-download-link/</guid><description>&lt;p&gt;Mozilla Firefox 13 is available for download on Mozilla FTP servers.&lt;/p&gt;
&lt;p&gt;Visual changes in this version is flatten buttons in toolbar, smooth scroll enabled by default, New Home Screen and a new look for New Tab page.&lt;/p&gt;
&lt;p&gt;&lt;img loading="lazy" src="http://lh3.ggpht.com/-ZtvAKZat82E/T8shzJAHPvI/AAAAAAAAGLU/LwHGFGJuuyM/s1600-h/FF13%25255B5%25255D.png" alt="" /&gt;
&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Download:&lt;/strong&gt; &lt;a href="https://ftp.mozilla.org/pub/mozilla.org/firefox/releases/13.0/win32/en-US/Firefox%20Setup%2013.0.exe" title="https://ftp.mozilla.org/pub/mozilla.org/firefox/releases/13.0/win32/en-US/Firefox%20Setup%2013.0.exe"&gt;Firefox Setup 13.0.exe&lt;/a&gt; [&lt;a href="http://www.filehippo.com/download_firefox/"&gt;Mirror&lt;/a&gt;]&lt;/p&gt;
&lt;p&gt;MD5: 89bc2ab1a1fa1e2d989d1c551f2a6ddf&lt;br&gt;
Size: 15.8MB&lt;/p&gt;</description></item><item><title>Facebook and Opera: Facebook Browser Is Imminent</title><link>https://omid.dev/2012/05/27/facebook-and-opera-facebook-browser-is-imminent/</link><pubDate>Sun, 27 May 2012 11:52:00 +0000</pubDate><guid>https://omid.dev/2012/05/27/facebook-and-opera-facebook-browser-is-imminent/</guid><description>&lt;p&gt;&lt;img loading="lazy" src="http://lh3.ggpht.com/-EL02lym5yAQ/T8IOXJ08DEI/AAAAAAAAGGg/tO_7IiTuM_4/s1600-h/facebook%252528low%252529%25255B2%25255D.jpg" alt="facebook(low)" /&gt;
&lt;/p&gt;
&lt;p&gt;Mashable: Are you ready for a Facebook browser that integrates the social networking behemoth into your online life more than ever? That’s exactly what could be on the way soon, according to one report.&lt;/p&gt;
&lt;p&gt;A Friday &lt;a href="http://www.pocket-lint.com/news/45795/facebook-browser-opera-software-buyout"&gt;&lt;em&gt;Pocket-lint&lt;/em&gt;&lt;/a&gt; report cites a “trusted source” that Facebook wants to buy Opera Software — manufacturers of the Opera web browser, which claims more than 200 million users worldwide. The Facebook browser would include default menu bar plugins, further permeating Facebook into users’ general web experience, according to the report.&lt;/p&gt;</description></item><item><title>Google releases security update for Chrome 19</title><link>https://omid.dev/2012/05/25/google-releases-security-update-for-chrome-19/</link><pubDate>Fri, 25 May 2012 09:13:00 +0000</pubDate><guid>https://omid.dev/2012/05/25/google-releases-security-update-for-chrome-19/</guid><description>&lt;p&gt;&lt;img loading="lazy" src="http://lh3.ggpht.com/-7faILWdsqaI/T79GOSXOInI/AAAAAAAAGFc/ftEHEhrBtRk/new-chrome-logo%25255B3%25255D.png?imgmax=800" alt="new-chrome-logo" /&gt;
&lt;/p&gt;
&lt;p&gt;&lt;a href="http://www.h-online.com/"&gt;H-Online&lt;/a&gt;: Google has &lt;a href="http://googlechromereleases.blogspot.co.uk/2012/05/stable-channel-update_23.html"&gt;announced an update&lt;/a&gt; to the stable version of Chrome, which brings the browser version to 19.0.1084.52 on Windows, Mac OS X and Linux. The update is a pure security update that does not include any new features – it closes nine vulnerabilities with a Common Vulnerability Scoring System (CVSS) rating of “High” and fixes two problems labelled “Critical” as well as two “Medium” level issues.&lt;/p&gt;
&lt;p&gt;Many of the vulnerabilities are due to bugs in Chrome&amp;rsquo;s memory handling, such as out-of-bounds reads and use-after-free conditions, and Google points out that several of them were detected with their &lt;a href="http://code.google.com/p/address-sanitizer/"&gt;AddressSanitizer&lt;/a&gt; tool. Other bugs were fixed in Chrome&amp;rsquo;s PDF handling code and its V8 JavaScript rendering engine.&lt;/p&gt;</description></item><item><title>Chrome 19 released with tab syncing</title><link>https://omid.dev/2012/05/17/chrome-19-released-with-tab-syncing/</link><pubDate>Thu, 17 May 2012 15:17:00 +0000</pubDate><guid>https://omid.dev/2012/05/17/chrome-19-released-with-tab-syncing/</guid><description>&lt;p&gt;&lt;img loading="lazy" src="http://lh5.ggpht.com/-P3oogfN-m3Q/T7UPfHlj5HI/AAAAAAAAGAI/0-nd-5EAC5E/s1600-h/new-chrome-logo%25255B2%25255D.png" alt="new-chrome-logo" /&gt;
&lt;/p&gt;
&lt;p&gt;The H-Online: Google has &lt;a href="http://chrome.blogspot.co.uk/2012/05/keeping-tabs-on-your-tabs.html"&gt;announced&lt;/a&gt; that Chrome 19 is the new stable version of its open source based web browser. As usual, the browser sees a number of &lt;a href="http://googlechromereleases.blogspot.co.uk/2012/05/stable-channel-update.html"&gt;security fixes&lt;/a&gt;: this time there are seven high-severity fixes specifically for Chrome including various use-after-free and out-of-bounds errors. Two fixes with a wider impact than Chrome are also mentioned – a workaround for a Linux NVIDIA driver bug and an “off-by-one out-of-bounds” write in libxml. In all, $7500 was paid out in rewards to security researchers, and Google notes it has also paid out $9000 to researchers to stamp out bugs before they reached its stable channel.&lt;/p&gt;</description></item><item><title>Chrome 18 update closes high-risk security holes</title><link>https://omid.dev/2012/05/01/chrome-18-update-closes-high-risk-security-holes/</link><pubDate>Tue, 01 May 2012 15:49:00 +0000</pubDate><guid>https://omid.dev/2012/05/01/chrome-18-update-closes-high-risk-security-holes/</guid><description>&lt;p&gt;&lt;img loading="lazy" src="http://lh3.ggpht.com/-mv8-JdAayAM/T5__CD9bF_I/AAAAAAAAFyg/eSExO5AJ3B0/s1600-h/new-chrome-logo%25255B2%25255D.png" alt="new-chrome-logo" /&gt;
&lt;/p&gt;
&lt;p&gt;The H-Online: Google has &lt;a href="http://googlechromereleases.blogspot.co.uk/2012/04/stable-channel-update_30.html"&gt;released a new update&lt;/a&gt; to the stable 18.x branch of its Chrome web browser to close a number of security holes found in the application. The update, labelled 18.0.1025.168, addresses a total of five vulnerabilities, three of which are rated as “&lt;a href="https://sites.google.com/a/chromium.org/dev/developers/severity-guidelines"&gt;high severity&lt;/a&gt;” by the company.&lt;/p&gt;
&lt;p&gt;These include use-after-free problems in &lt;a href="http://en.wikipedia.org/wiki/Floating_point"&gt;floating point&lt;/a&gt; handling and the XML parser; all of these bugs were detected using the &lt;a href="http://code.google.com/p/address-sanitizer/wiki/AddressSanitizer"&gt;AddressSanitizer&lt;/a&gt;. As part of its &lt;a href="https://sites.google.com/a/chromium.org/dev/Home/chromium-security"&gt;Chromium Security Vulnerability Rewards program&lt;/a&gt;, Google paid a security researcher by the name of “miaubiz”, who is number three in the company&amp;rsquo;s &lt;a href="http://www.chromium.org/Home/chromium-security/hall-of-fame"&gt;Security Hall of Fame&lt;/a&gt;, $1,000 for discovering and reporting one of the float handling problems. Two medium risk problems related to IPC validation and a race condition in sandbox IPC have also been corrected.&lt;/p&gt;</description></item><item><title>Mozilla to auto-upgrade Firefox 3.6 users to version 12</title><link>https://omid.dev/2012/04/30/mozilla-to-auto-upgrade-firefox-3-6-users-to-version-12/</link><pubDate>Mon, 30 Apr 2012 17:32:00 +0000</pubDate><guid>https://omid.dev/2012/04/30/mozilla-to-auto-upgrade-firefox-3-6-users-to-version-12/</guid><description>&lt;p&gt;&lt;img loading="lazy" src="http://lh6.ggpht.com/-9Tg-vaq_gBU/T57FsRsK6SI/AAAAAAAAFxc/NvRULfftH4I/s1600-h/Firefox_Logo_200%25255B2%25255D.png" alt="Firefox_Logo_200" /&gt;
&lt;/p&gt;
&lt;p&gt;H-Online: Soon, users running Firefox 3.6.x will start being automatically upgraded to the current &lt;a href="https://omid.dev/2012/04/firefox-and-thunderbird-12-are-out.html"&gt;version 12.0 release&lt;/a&gt; of the open source web browser. The plan to auto-update these users has been being discussed since the end of March, when Mozilla Release Manager Alex Keybl proposed the move on a Mozilla &lt;a href="https://groups.google.com/group/mozilla.dev.planning/browse_thread/thread/1fb8dda6f4f735b7/fd3284b0919a272b?q=%22firefox&amp;#43;3.6%22&amp;amp;lnk=ol&amp;amp;&amp;amp;pli=1"&gt;planning discussion thread&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;&lt;a href="http://www.computerworld.com/s/article/9226666/Mozilla_to_kill_Firefox_3.6_by_auto_upgrading_old_browser"&gt;According to Keybl&lt;/a&gt;, Firefox 3.6.x users with updates enabled should start being upgraded in early May – the specific date has yet to be confirmed. The 3.6.x branch of Firefox, the first release of which arrived in January 2010, reached its end of life last week on 24 April; the last update to the 3.6 series was version 3.6.28 from early March.&lt;/p&gt;</description></item><item><title>Security improvements in Opera 12 beta</title><link>https://omid.dev/2012/04/26/security-improvements-in-opera-12-beta/</link><pubDate>Thu, 26 Apr 2012 14:54:00 +0000</pubDate><guid>https://omid.dev/2012/04/26/security-improvements-in-opera-12-beta/</guid><description>&lt;p&gt;&lt;img loading="lazy" src="http://lh3.ggpht.com/-tU7UCFSAfzA/T5lal7r-8BI/AAAAAAAAFss/7FP6rXSB0SU/s1600-h/Opera-logo-new200%25255B3%25255D.png" alt="Opera-logo-new200" /&gt;
&lt;/p&gt;
&lt;p&gt;The H-Online: A beta of version 12 of the &lt;a href="http://www.opera.com/"&gt;Opera&lt;/a&gt; web browser &lt;a href="http://my.opera.com/desktopteam/blog/2012/04/26/opera-12-beta"&gt;has been released&lt;/a&gt; with privacy and security-focused improvements. Code-named “Wahoo”, the Opera 12.00 beta now runs plugins out-of-process and includes optimizations for better SSL handling. Running plugins in their own process not only improves the smoothness and stability of the browser but can limit the damage some plugin exploits can do. Privacy is enhanced with support for the “Do Not Track” (DNT) header, which is used to tell web sites that the browser user wishes to opt-out of online behavioral tracking.&lt;/p&gt;</description></item><item><title>Google Chrome fixes seven high-risk vulnerabilities</title><link>https://omid.dev/2012/04/06/google-chrome-fixes-seven-high-risk-vulnerabilities/</link><pubDate>Fri, 06 Apr 2012 20:28:00 +0000</pubDate><guid>https://omid.dev/2012/04/06/google-chrome-fixes-seven-high-risk-vulnerabilities/</guid><description>&lt;p&gt;&lt;img loading="lazy" src="http://lh6.ggpht.com/-oBFEuHM2jXA/T39Ky857ckI/AAAAAAAAFbE/2TO8aqTx9KY/s1600-h/new-chrome-logo%25255B3%25255D.png" alt="new-chrome-logo" /&gt;
&lt;/p&gt;
&lt;p&gt;The H-Online: Google &lt;a href="http://googlechromereleases.blogspot.co.uk/2012/04/stable-and-beta-channel-updates.html"&gt;has announced updates&lt;/a&gt; to the Stable and Beta channels of their Chrome browser, fixing several bugs and twelve security vulnerabilities. Seven of the twelve security fixes were classed as high-risk problems and Google paid a total of $6000 to the researchers who discovered the bugs.&lt;/p&gt;
&lt;p&gt;The update also includes a new version of the bundled Flash Player. Adobe have revised the Flash Player advisory from the &lt;a href="http://www.h-online.com/news/item/Patch-for-Adobe-Flash-closes-two-critical-security-holes-1486334.html"&gt;end of March&lt;/a&gt; to include fixes for a Chrome/Flash only pair of memory corruption issues listed as CVE-2012-0724 and CVE-2012-0725. Given that these issues only affect Chrome and Chrome manages its own update, it is unlikely that Adobe will be reissuing or updating the advisory or patches for other browsers and platforms.&lt;/p&gt;</description></item></channel></rss>