Chrome 72 Released with 58 Security fixes, Removes HPKP and Deprecate TLS 1.0 and 1.1

Google released Chrome 72 stable version for Windows, Mac, and Linux. The Chrome 72.0.3626.81 comes with the fix for 58 security bugs and includes a number of improvements.

The release includes some major updates that includes Deprecate of the TLS 1.0 and 1.1 protocols and HTTP-Based Public Key Pinning.

Depreciation of TLS 1.0, TLS 1.1 and HPKP

Starting from Google Chrome 72, the chrome has taken the first step in removing the support for TLS 1.0 and TLS 1.1 protocols. During the depreciation period if any sites using TLS 1.0 and 1.1 shows a warning in browser devtools.

After the depreciation period, in 2020, if any sites using TLS 1.0 and 1.1 will fail to connect with the and the website administrators need to upgraded with TLS 1.2.

HPKP support was removed, it is a security feature that prevents the misissuance of the certificate but the adoption rate is very low.

Chrome to remove the support for rendering resources from FTP servers and instead allows users to download them directly.

Popups during page unload are blocked, “the popup blocker already prohibited this, but now it is prohibited whether or not the popup blocker is enabled.”

Chrome Web Authentication API which adds support for communicating with external devices over BLE, including a UI to guide users in pairing and using their devices for two-factor authentication.

Chrome 72 comes with a fix for 58 security bugs that identified from internal audits, fuzzing and other initiatives such as AddressSanitizer, MemorySanitizer, UndefinedBehaviorSanitizer, Control Flow Integrity, libFuzzer, or AFL.

Firefox 65.0 released few hours before the Chrome update, the Firefox updates fixes several security vulnerabilities along with various new futures including video streaming experience, updated language preference etc.

You can follow us on LinkedinTwitterFacebook for daily Cybersecurity updates also you can take the Best Cybersecurity courses online to keep your self-updated.

Gurubaran

Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

Recent Posts

Hunters International Claims Tata Technologies Cyberattack

Multinational engineering and technology services firm Tata Technologies has reportedly fallen victim to a significant…

2 hours ago

Authorities Seize $31 Million Linked to Crypto Exchange Hack

U.S. authorities announced the seizure of $31 million tied to the 2021 Uranium Finance decentralized…

2 hours ago

Google, Meta, and Apple Power the World’s Biggest Surveillance System

Imagine a government that tracks your daily movements, monitors your communications, and catalogs your digital…

3 hours ago

Docusnap for Windows Flaw Exposes Sensitive Data to Attackers

A recently disclosed vulnerability in Docusnap's Windows client software (CVE-2025-26849) enables attackers to decrypt sensitive…

4 hours ago

CISA Warns of Active Exploitation of Microsoft Windows Win32k Vulnerability

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2018-8639, a decade-old Microsoft Windows privilege…

4 hours ago

Update Alert: Google Warns of Critical Android Vulnerabilities Under Exploit

Google’s March 2025 Android Security Bulletin has unveiled two critical vulnerabilities—CVE-2024-43093 and CVE-2024-50302—currently under limited,…

7 hours ago