NEWS - January 11, 2013
by Carol~ - 1/11/13 5:27 AM
Stable Chrome 24 supports MathML and closes security holes
The latest stable release of Google's Chrome browser brings support for mathematical notation with the MathML XML markup language, along with expanded datalist support. The developers have closed 25 security holes, most of which have been discovered using the AddressSanitizer tool. Google paid out a total of $6000 to the security researchers who discovered three of the eleven vulnerabilities rated with a high priority.
Two Facebook employees earned $4000 for discovering a same origin policy bypass that could be performed with a malformed URL (CVE-2012-5146). $1000 was paid for each of the use-after-free bugs that were discovered in SVG layout and DOM handling of the browser.
MathML support in Chrome 24 allows developers to express mathematical notation on web pages that are then rendered consistently in the browser. Expanded datalist support allows web developers to set specific dates and times for input elements and gives users the ability to enter arbitrary dates and times instead, if they wish to do so. Chrome also includes an updated Flash player (version 220.127.116.11) and miscellaneous speed and stability improvements. Information on all changes introduced with the update is available in the Chromium SVN revision log.
Continued : http://www.h-online.com/security/news/item/Stable-Chrome-24-supports-MathML-and-closes-security-holes-1781648.html
Also: Chrome 24 Fixes More Than 20 Flaws
See Vulnerabilities & Fixes: Google Chrome Multiple Vulnerabilities