Security fixes and rewards:
Please see the Chromium security page for more detail. Note that the referenced bugs may be kept private until a majority of our users are up to date with the fix.
Occasionally, we issue special rewards for bugs outside of Chrome, particularly where the bug is very severe and/or we are able to partially work around the issue:
- [Mac OS only] [$1000]  High CVE-2012-5115: Defend against wild writes in buggy graphics drivers. Credit to miaubiz.
And back to your regular scheduled rewards, including some at the new higher levels:
- [$3500]  Medium CVE-2012-5127: Integer overflow leading to out-of-bounds read in WebP handling. Credit to Phil Turnbull.
- [Linux 64-bit only] [$1500]  Medium CVE-2012-5120: Out-of-bounds array access in v8. Credit to Atte Kettunen of OUSPG.
- [$1000]  High CVE-2012-5116: Use-after-free in SVG filter handling. Credit to miaubiz.
- [Mac OS only] [$1000]  High CVE-2012-5118: Integer bounds check issue in GPU command buffers. Credit to miaubiz.
- [$1000]  High CVE-2012-5121: Use-after-free in video layout. Credit to Atte Kettunen of OUSPG.
-  Low CVE-2012-5117: Inappropriate load of SVG subresource in img context. Credit to Felix Gröbert of the Google Security Team.
-  Medium CVE-2012-5119: Race condition in Pepper buffer handling. Credit to Fermin Serna of the Google Security Team.
-  Medium CVE-2012-5122: Bad cast in input handling. Credit to Google Chrome Security Team (Inferno).
-   Medium CVE-2012-5123: Out-of-bounds reads in Skia. Credit to Google Chrome Security Team (Inferno).
-  High CVE-2012-5124: Memory corruption in texture handling. Credit to Al Patrick of the Chromium development community.
-  Medium CVE-2012-5125: Use-after-free in extension tab handling. Credit to Alexander Potapenko of the Chromium development community.
-  Medium CVE-2012-5126: Use-after-free in plug-in placeholder handling. Credit to Google Chrome Security Team (Inferno).
-  High CVE-2012-5128: Bad write in v8. Credit to Google Chrome Security Team (Cris Neckar).
Many of the above bugs were detected using AddressSanitizer.
The security issues in V8 have been fixed in v8-22.214.171.124.
We’d also like to thank miaubiz for working with us during the development cycle and preventing security regressions from ever reaching the stable channel. Rewards were issued.
This version also has a new Adobe Flash. More details can be found here.
Full details about what changes are in this release are available in the SVN revision log. Interested in hopping on the stable channel? Find out how. If you find a new issue, please let us know by filing a bug.