Google paid out a record £16,215 ($26,511) in bug bounties to researchers who reported some of the 18 Chrome vulnerabilities patched today.
The company also upgraded the stable version of the browser to version 15, which sports a revamped New Tab page.
Google last refreshed Chrome on 16 September, just over five weeks ago. Google produces an update to its “stable” channel about every six weeks, a practice that rival Mozilla copied with the debut of Firefox 5 last June.
Eleven of the 18 vulnerabilities were rated “high,” the second-most-serious ranking in Google’s scoring system, while three were tagged “medium” and another four were marked “low.”
Google paid £16,215 in bounties, a record, to four researchers, including £8,528 ($13,674) to Sergey Glazunov and £6,447 ($10,337) to “miaubiz,” a pair of regular Chrome vulnerability finders who together have accounted for 57 percent of all bug payments this year. Google has laid out over £106,018 ($170,000) in bounties so far during 2011.
The previous bounty record, set more than two months ago, was £10,602 ($17,000).
Glazunov and miaubiz collected their five-figure checks for reporting multiple bugs that Google then combined into one CVE (Common Vulnerabilities Exposures) identifier.
Glazunov, for example, was awarded £7,575 ($12,147) for five bugs that Google named only as “cross-origin policy violations” and pooled under a single CVE in its typically terse description.
Miaubiz, meanwhile, was paid £3,952 ($6,337) for one CVE that actually contained six different bugs tracked by Google in its change database.
As is its habit, Google barred access to the bug tracker database for all the vulnerabilities to prevent outsiders from obtaining details on the flaws.
Most of the bugs uncovered by miaubiz, said Google, were discovered using the company’s memory error detection tool, AddressSanitizer, that it released in June.
AddressSanitizer can detect a variety of errors, including “use-after-free” memory management bugs like the ones reported by miaubiz.
Google also said it updated Chrome to stymie BEAST, for “Browser Exploit Against SSL/TLS,” a hacking tool released last month that attacks browsers and decrypts cookies, potentially giving attackers access to encrypted website log-on credentials.
Previously, Google had added anti-BEAST protection to Chrome’s “dev” and “beta” channels, the rougher-edged versions that precede the stable build.
Microsoft has promised to patch Windows so that its Internet Explorer isn’t vulnerable to BEAST’s attacks, but has not set a timetable.
Chrome 15′s most obvious change, however, is the redesigned New Tab page that appears when users click the right-most tab at the top of the browser’s window or press the Ctrl-T key combination.
The new format offers easier navigation between online apps and most-used websites, the ability to organize apps by dragging and dropping, and a simpler way to remove apps or site from the screen.
Chrome 15 can be downloaded for Windows, Mac OS X and Linux from Google’s Web site. Users already running the browser will be updated automatically via the browser’s behind-the-scenes service.
The cover was yanked off the stable version of Chrome 15 today, as Google updated its New Tab page to emphasize Web apps and customizations along with Most Visited sites. Google Chrome 15 stable for Windows (download), Mac (download), Linux (download), and Chrome Frame also made several serious security improvements. However, the ability to synchronize your Omnibox history remains relegated to the less-stable Chrome beta and developer’s channels.
The intuitive New Tab page allows you to create custom categories by dragging and dropping apps and bookmarks, and includes navigation arrows on the left and right edges of the page that become more visible on mouse-over.
The New Tab redo launch coincides with a redesign of the Chrome Web Store, Google’s clearinghouse for its Web apps. The new look to the Web Store emphasizes a more graphical look, including app-related video, screenshots, and reviews that are linked to the Google+ account of the reviewer. Along with the killing of Buzz, Google hopes the move will help focus people on the interactivity of Google’s Web services.