Monday, November 25, 2024
HomeSecurity NewsChrome 66 Released with Number of Security Fixes and Starts Distrust Symantec...

Chrome 66 Released with Number of Security Fixes and Starts Distrust Symantec SSL/TLS Certificates

Published on

Google announced Chrome 66 to the stable channel for Windows, Mac, Linux, and users started upgrading to the new a version of Chrome 66.0.3359.117 that comes with a number of security fix and improvements.

Chrome 66 Targets Security 

With Chrome 66 site isolation turned on for a small percentage of users to prepare for a broader upcoming launch.

Strict site isolation which allows each website to have a dedicated process isolated from other sites, it was introduced in version 63 but not enabled by default.

Open Chrome.
In the address bar at the top, enter chrome://flags/#enable-site-per-process and press Enter.
Next to “Strict site isolation,” click Enable.
If you don’t see “Strict site isolation,” update Chrome.
Click Relaunch now.
- Advertisement - SIEM as a Service
Chrome 66

The massive change is with the certificate that was issued by Symantec before June 1, 2016, those will stop function with Chrome 66 and from Chrome 70 all remaining Symantec SSL/TLS certificates will stop working. Chrome 70 set to be released on Aug 30th, 2018.

Chrome 66

The release includes the fix for 62 security bugs that reported by the security researchers and Google says “bug details and links may be kept restricted until a majority of users are updated with a fix”.

You can find the complete list of changelog here and here for Security Fixes. It includes a number of fixes such as SmartScreen bypass in the download, URL spoof in Navigation, Fullscreen UI spoof and Confusing autofill settings.

From Chrome 66 it begins alerting users if any third party software tries to inject any code in Chrome and asks users to remove the software.

Starting from Chrome 68 which set to release by July 2018 it begins to block the third-party software from injecting into chrome and starting from Chrome 72 this option will be removed and it always block code injection.

Also, they announced safe browsing by default in the WebView starting this April 2018 from the WebView version 66. This means Android app developers using WebView not required to make any protection.

Gurubaran
Gurubaran
Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

Latest articles

Threat Actors Exploit Google Docs And Weebly Services For Malware Attacks

Phishing attackers used Google Docs to deliver malicious links, bypassing security measures and redirecting...

Python NodeStealer: Targeting Facebook Business Accounts to Harvest Login Credentials

The Python-based NodeStealer, a sophisticated info-stealer, has evolved to target new information and employ...

XSS Vulnerability in Bing.com Let Attackers Send Crafted Malicious Requests

A significant XSS vulnerability was recently uncovered in Microsoft’s Bing.com, potentially allowing attackers to...

Meta Removed 2 Million Account Linked to Malicious Activities

 Meta has announced the removal of over 2 million accounts connected to malicious activities,...

Free Webinar

Protect Websites & APIs from Malware Attack

Malware targeting customer-facing websites and API applications poses significant risks, including compliance violations, defacements, and even blacklisting.

Join us for an insightful webinar featuring Vivek Gopalan, VP of Products at Indusface, as he shares effective strategies for safeguarding websites and APIs against malware.

Discussion points

Scan DOM, internal links, and JavaScript libraries for hidden malware.
Detect website defacements in real time.
Protect your brand by monitoring for potential blacklisting.
Prevent malware from infiltrating your server and cloud infrastructure.

More like this

Nearest Neighbor Attacks: Russian APT Hack The Target By Exploiting Nearby Wi-Fi Networks

Recent research has revealed that a Russian advanced persistent threat (APT) group, tracked as...

Critical PDF.js & React-PDF Vulnerabilities Threaten Millions Of PDF Users

A new critical vulnerability has been discovered in PDF.js, which could allow a threat...

LayerX Security Raises $26M for its Browser Security Platform, Enabling Employees to Work Securely From Any Browser, Anywhere

LayerX, pioneer of the LayerX Browser Security platform, today announced $24 million in Series...