Chrome 70.0.3538.67 穩定版本已經發布,未來幾天/幾周內將推送到 Windows、Mac 和 Linux 設備上。
在新發布的Chrome 70瀏覽器中,谷歌面向所有用戶開放了畫中畫功能。在此前的Chrome 69版本中該功能仍處於測試狀態,需要用戶激活相應的Flag才能激活。在畫中畫模式下,您可以在屏幕上拖動位置、播放和暫停,也可以通過拉伸邊緣調整視頻大小,或單擊右上角的「X」按鈕關閉視頻。
另外,70還支持在Windows 10平臺上安裝Progressive Web Apps(PWA)。谷歌表示安裝在桌面的網頁應用使用體驗非常接近於本地應用,並且應用的服務商可以緩存所有資源因此這些PWA應用有很好的兼容性和可靠性。
谷歌表示移動領域的增長速度驚人,但是桌面市場仍處於緩慢增長的狀態。桌面依然是家庭和辦公環境中完成日常任務的重要設備。通過桌面訪問PWA應用能夠給用戶提供接近於本地應用的使用體驗,而且兼容性、可靠性都令人滿意。
Chrome 70中的新功能允許用戶安裝PWA應用。這就意味著當你打開Spotify或者Twitter等頁面,用戶可以點擊安裝當做常規本地應用進行使用。用戶之後可以通過開始菜單進行觸發使用。Google解釋道:「服務提供商確保這些PWA應用快速、可靠,應用窗口體驗會非常接近其他已經安裝的應用。」
此更新包含 23 個安全修復程序,以下是由外部研究人員提供的修復:
[$N/A][888926] High CVE-2018-17462: Sandbox escape in AppCache. Reported by Ned Williamson and Niklas Baumstark working with Beyond Security’s SecuriTeam Secure Disclosure program on 2018-09-25
[$N/A][888923] High CVE-2018-17463: Remote code execution in V8. Reported by Ned Williamson and Niklas Baumstark working with Beyond Security’s SecuriTeam Secure Disclosure program on 2018-09-25
[$3500][872189] High CVE to be assigned: Heap buffer overflow in Little CMS in PDFium. Reported by Quang Nguyễn (@quangnh89) of Viettel Cyber Security on 2018-08-08
[$3000][887273] High CVE-2018-17464: URL spoof in Omnibox. Reported by xisigr of Tencent's Xuanwu Lab on 2018-09-20
[$3000][870226] High CVE-2018-17465: Use after free in V8. Reported by Lin Zuojian on 2018-08-02
[$1000][880906] High CVE-2018-17466: Memory corruption in Angle. Reported by Omair on 2018-09-05
[$3000][844881] Medium CVE-2018-17467: URL spoof in Omnibox. Reported by Khalil Zhani on 2018-05-19
[$2000][876822] Medium CVE-2018-17468: Cross-origin URL disclosure in Blink. Reported by James Lee (@Windowsrcer) of Kryptos Logic on 2018-08-22
[$1000][880675] Medium CVE-2018-17469: Heap buffer overflow in PDFium. Reported by Zhen Zhou of NSFOCUS Security Team on 2018-09-05
[$1000][877874] Medium CVE-2018-17470: Memory corruption in GPU Internals. Reported by Zhe Jin(金哲),Luyao Liu(劉路遙) from Chengdu Security Response Center of Qihoo 360 Technology Co. Ltd on 2018-08-27
[$1000][873080] Medium CVE-2018-17471: Security UI occlusion in full screen mode. Reported by Lnyas Zhang on 2018-08-10
[$1000][822518] Medium CVE-2018-17472: iframe sandbox escape on iOS. Reported by Jun Kokatsu (@shhnjk) on 2018-03-16
[$500][882078] Medium CVE-2018-17473: URL spoof in Omnibox. Reported by Khalil Zhani on 2018-09-08
[$500][843151] Medium CVE-2018-17474: Use after free in Blink. Reported by Zhe Jin(金哲),Luyao Liu(劉路遙) from Chengdu Security Response Center of Qihoo 360 Technology Co. Ltd on 2018-05-15
[$500][852634] Low CVE-2018-17475: URL spoof in Omnibox. Reported by Vladimir Metnew on 2018-06-14
[$500][812769] Low CVE-2018-17476: Security UI occlusion in full screen mode. Reported by Khalil Zhani on 2018-02-15
[$500][805496] Low CVE-2018-5179: Lack of limits on update() in ServiceWorker. Reported by Yannic Bonenberger on 2018-01-24
[$N/A][863703] Low CVE-2018-17477: UI spoof in Extensions. Reported by Aaron Muir Hamilton <aaron@correspondwith.me> on 2018-07-14
內容綜合整理自:
https://chromereleases.googleblog.com/2018/10/stable-channel-update-for-desktop.html
https://www.cnbeta.com/articles/tech/778163.htm
https://www.cnbeta.com/articles/tech/778173.htm
開源中國徵稿開始啦!
開源中國 www.oschina.net 是目前備受關注、具有強大影響力的開源技術社區,擁有超過 200 萬的開源技術精英。我們傳播開源的理念,推廣開源項目,為 IT 開發者提供一個發現、使用、並交流開源技術的平臺。
現在我們開始對外徵稿啦!如果你有優秀的技術文章想要分享,熱點的行業資訊需要報導等等,歡迎聯繫開源中國進行投稿。投稿詳情及聯繫方式請參見:我要投稿