Chipp.in Tech News and Reviews

Windows, Security & Privacy, Open Source and more

Menu
  • Home
  • Windows
  • Security & Privacy
  • Gaming
  • Guides
  • Windows 11 Book
  • Contact
  • RSS Feed
Menu

Tag: chrome

Chrome for Android may move and delete Tabs automatically

Posted on September 18, 2024September 18, 2024 by Martin Brinkmann

Google released Chrome 129 today for Android and desktop systems. The update fixes a few security issues and introduces new features and changes as well.

One change in particular affects users of Chrome on Android: the automatic handling of inactive tabs.

Once updated to Chrome 129 on Android, the browser will move inactive tabs to a new group automatically. There, the tabs remain for a period of 60 days before they are deleted automatically according to Google.

Tip: Switching from Chrome to Firefox is easier than ever before. If you worry about disabled or crippled extensions, Firefox is your best bet to avoid this.

Note: Whether the deleting is enabled by default is unclear. Google says that the tabs will get deleted automatically, but it was disabled in Chrome 129 Beta.

When is a tab considered inactive? Google moves tabs to the Inactive Tabs group after 14 days of inactivity. Inactivity means that the tab was not activated in that time in Chrome.

Chrome for Android's new Inactive menu.

Good news is that you may change the functionality in the settings. Here is how that is done:

  1. Open Google Chrome on the Android device.
  2. Select Menu > Settings to open the preference.
  3. Activate Tabs there to display tab-related settings.
  4. Tap on Inactive to customize the functionality.
  5. Set the period to 7 days, 14 days, 30 days, or never. The default is 14 days.
  6. Toggle “Close after 60 days” to enable or disable the auto-delete feature.

Google says that the feature is designed to reduce Chrome’s memory usage and to improve the accessibility of tabs in the browser.

Deleted tabs remain accessible through the browsing history, but only if it has not been deleted.

Chrome users who do not want inactive tabs to be moved to the new group should set the functionality to Never. This ensures that Chrome won’t move inactive tabs out of sight or delete them after the inactivity period.

How do you handle tabs in your browser? Keep everything open? Use bookmarks? Start afresh on every start? Feel free to leave a comment below.

0.0.0.0 Day: decade-old vulnerability affects all browsers

Posted on August 9, 2024August 9, 2024 by Martin Brinkmann

Security researchers have disclosed a vulnerability that affects all modern browsers. What makes it particularly worrisome is that it has been known for 18 years; that goes back to a time before Google even thought of creating Chrome.

The details:

  • The researchers call the issue 0.0.0.0 Day.
  • It allows malicious websites to interact with services that run on the local network.
  • This could lead to unauthorized access or remote code execution attacks on local services from outside the local network.

In other words: the security issue allows the circumvention of security protections by malicious websites. Chromium’s Private Network protection does not protect against this, neither does Firefox. Apple’s Safari browser was also vulnerable, but the company has released a patch that blocks access to 0.0.0.0.

The blog post provides a technical description of the vulnerability. It also explains why it took this long to react on it.

The researchers found a Mozilla bug listing that dates back 18 years. It shows that the developers were not sure whether the reported bug was a security issue, a bug, or no flaw at all.

How Google, Mozilla, and Apple plan to react

Researchers at Oligo disclosed the vulnerability to security teams of major browsers in April 2024.

  • Google: plans to block access starting in Chrome 128 and finalize the rollout by Chrome 133. Other Chromium-based browsers will get this as well.
  • Apple: has implemented a change that blocks destination host IP addresses, if the IP is all zeroes.
  • Mozilla: fix is in progress. Firefox is special, as it never restricted Private Network Access in first place. Will implement Private Network Access, but no ETA on this one.

The fixes are important, but so is standardization of the issue. HTTP requests to 0.0.0.0 should be added to security standards according to the security researchers.

Closing Words

The security researchers note that use of 0.0.0.0 on the Web is on the rise. They use counters provided by Chromium for this. According to those, it is used by 0.015% of all websites. While that may not sound like much, it equates to roughly 100,000 public websites that may communicate with 0.0.0.0.

Malicious actors may exploit the issue in their attacks. Oligo points out that ShadowRay, a recent attack that targets AI workloads, could be executed from browsers using 0.0.0.0 as the attack vector.

It is unclear if browser extensions such as Port Authority for Firefox provide protection against this kind of attack.

What is your take on this new vulnerability? Seems that there is always something new, or shall I say old, that is affecting the security of browsers. (via Born)

Chrome

Keep on blocking in a free world: how to switch from Chrome to Firefox

Posted on August 3, 2024August 3, 2024 by Martin Brinkmann

Google Chrome users who have extensions installed may soon have some or even all of their installed extensions disabled by Google.

While all browser extensions may be impacted, it is ad blockers and privacy extensions that are impacted the most.

One example: uBlock Origin, arguably the most loved and powerful content blocker available for browsers, will not be offered anymore for Chrome and all other Chromium-based browsers.

This means that you cannot install the browser extension anymore in Chrome, Microsoft Edge, Vivaldi, Opera, and myriads others.

One exemption: Brave Software revealed recently that it plans to continue support for uBlock Origin. This would be the one exemption at the time of writing.

The developer of uBlock Origin has created a lite-version of the extension. Called uBlock Origin Lite, it remains available for Chrome. Its functionality is reduced, however.

Furthermore, users of Chrome who use uBlock Origin need to download and install uBlock Origin Lite manually. A click on the “find alternative” button in Chrome

How to find out if you are impacted by the change

Chrome Extensions Support
Google Chrome highlights extensions that will soon no longer be compatible with the browser

Do the following to find out if extensions that you have installed in Chrome are impacted:

  • Load chrome://extensions/ in the browser’s address bar. You may also open the page manually by going to Menu > Extensions > Manage Extensions.
  • If you see “These extensions may soon no longer be supported” at the top, you are affected by the change.

Tip: you can check out a detailed guide about this here.

Google lists all incompatible extensions. Each features a “find alternative” button, which opens a special page on the Chrome Web Store that highlights extensions that continue to remain compatible with Chrome in the future.

For uBlock Origin, Google suggests the following options:

  • uBlock Origin Lite
  • Adblock Plus
  • Stands Adblocker
  • Ghostery Tracker & Adblocker

While all block ads, none offers the functionality of uBlock Origin.

What you can do about it

You have just a few options at this point:

  1. Keep on using Chrome until Google disables the extensions. You may then extend support for about a year using Enterprise policies.
  2. Keep on using Chrome and use a different browser extension that works for you, hoping that Google does not introduce any other changes in the future that may impact it.
  3. Switch to Brave Browser. This is a valid option only if you want to keep on using uBlock Origin, AdGuard, uMatrix, or NoScript.
  4. Switch to Firefox or a Firefox-based browser. The extensions, including uBlock Origin, remain available and maintained for Firefox.

The first option is valid for all Chromium-based browsers, but it is temporary only. Google will remove the Enterprise policy next year, and that marks the end of support in Chrome.

As you see, you have a few options only. While you could keep on using a Chromium-based browser, Brave Browser, it is unclear for how long Brave will support the four special extensions.

Admittedly, it is also unclear for how long Mozilla will support the old extensions system. If it sees an uptick in users, as some Chrome users may migrate to Firefox because of the changes Google implements, it could very well be for a long time.

Are you affected by the change? Do you have any extensions that you rely on that would make you switch browsers, if your current favorite would not support them anymore? Feel free to leave a comment down below.

Google is testing a compact mode in Chrome

Posted on July 27, 2024July 27, 2024 by Martin Brinkmann

Whenever there is an option to turn on a compact mode, I pick it. The main reason for that is that compact mode removes whitespace so that more content is displayed on the screen at the same time.

Google is testing a compact mode for its Chrome web browser. An experimental flag was added in Chrome Canary that adds the mode to the browser.

Compact Mode reduces the height of the user interface elements tabstrip and other toolbars, including the bookmarks toolbar. Google says that this frees up space for web content.

Here is how you enable it:

  1. Load chrome://flags/#compact-mode in the browser’s address bar.
  2. Set the status of the experimental flag to Enabled.
  3. Restart Google Chrome.
  4. Right-click on a blank spot on the tabstrip and select Toggle Compact Mode.

The change is immediate, a restart of the browser is not required. Repeat the steps listed above to restore the regular interface of the Chrome browser.

Chrome Compact Mode vs. Normal Mode

Here is a before and after screenshot for comparison:

The normal Chrome user interface
The normal Chrome user interface
The new Compact interface of the Chrome browser
The new Compact interface of the Chrome browser

The height of the toolbars is reduced, which means that they take up less space. It is a useful feature for users who want compact toolbars to free up room for web content displayed in the browser.

Note: Google lists compact mode as a prototype right now. Since it is an experimental flag, it is not guaranteed that the feature will make it into stable Chrome. It could change before it lands or it could be pulled entirely by Google before Stable users can set their sights on the feature.

Closing Words

I prefer compact modes, but this is not enough to convince me to make Chrome my default browser. It would go too far to list my reasons here, but I prefer browsers that are not run by advertising companies.

What is your preference? Compact Mode all the time or do you prefer other modes? Feel free to leave a comment down below.

Chrome

Report: Google sneaked in code in Chrome that is favoring Google

Posted on July 10, 2024July 10, 2024 by Martin Brinkmann

A report suggests that Google has sneaked code into Chromium-based browsers that is favoring Google-owned properties. Browsers like Chrome, Brave, and Microsoft Edge appear affected.

If true, it would give critics of Google’s dominance in web browsing a mighty powerful argument.

Here are the details: Google Chrome and other Chromium-based browsers give *.google.com sites full access to system / tab CPU usage, GPU usage, memory usage, detailed processor information, and a logging backchannel.

Luca Casonato published information about this on X and Simon Willison published code that anyone may run to verify the claim.

Chrome returning information on google-owned properties
The information that Chrome reveals to Google when the code is run

Here is how that is done:

  1. Open Google Chrome on your system.
  2. Load https://www.google.com/ or any other *.google.com property.
  3. Select Menu > More Tools > Developer Console.
  4. Switch to the Console tab, if it is not active already.
  5. Type allow pasting.
  6. Paste the following code: chrome.runtime.sendMessage(‘nkeimhogjdpnpccoofpliimaahmaaome’, {method: ‘cpu.getInfo’}, response => {console.log(JSON.stringify(response, null, 2));});
  7. Press the Enter-key.

Chrome returns information when the code is run on a Google property. It returns an error message when you run it on any other site.

The code is accessible on the Chromium Code Search website. You can load it here and check it out yourself.

Casonato suggests that the exclusive feature is a violation of the Digital Markets Act as browser vendors “must give the same capabilities to everyone”.

Closing Words

It is unclear if and how Google is using the information. Casonato says that he does not believe that the company uses it for something malicious or invasive, such as fingerprinting.

Still, Google favoring Google in Chrome and Chromium-based browsers is giving critics of Google’s dominance in web browsing another reason why a browser monopoly or duopoly (if you consider Safari), is bad for users.

It is also interesting to note that other Chromium-based browsers have kept the code in their browsers. It is unclear why.

Which browser do you use mainly and why?

Google Chrome 126

Google Chrome 126 fixes 21 security issues

Posted on June 12, 2024June 12, 2024 by Martin Brinkmann

Google released a new stable version of its Chrome web browser for all supported platforms. Chrome 126 is a security update first and foremost, but it makes non-security changes to the browser as well.

The security update is available already. Google rolls out these updates over the course of days and weeks. Most Chrome installations are updated automatically, thanks to the built-in updating system.

Desktop users may install the update quicker by opening Menu > Help > About Google Chrome. Chrome displays the installed version on the page that opens and runs a check for updates. The browser will download any new version it finds.

Chrome 126: the security fixes

Google mentions that it has fixed 21 unique security issues in Chrome 126. It lists only externally reported issues on the page. All of these are rated high or lower, and there does not seem to be a(nother) 0-day issue that is affecting the browser at this time.

The security issues rated high type confusion, use after free, heap buffer overflow, and inappropriate implementation issues.

The non-security changes of Chrome 126

Here is an overview of important non-security changes in the new Chrome release:

  • OCR-AI Reader for inaccessible PDF documents that creates a “built-in PDF screen reader”.
  • Beginning to switch to an out-of-process iframe architecture for the PDF viewer. This makes it simpler to add new features to it according to Google.
  • Reactive prefetch on desktop. The feature speeds up navigations and the loading of pages by using a Google-owned service to predict resources that should be prefetched.
  • Tab Group support on iPad.
  • Starting in Chrome 126, Chrome starts to directly support accessibility client software that uses Microsoft Windows’s UI Automation accessibility framework.
  • Search any text or image using Google Lens.

Developers may want to check out the Chrome Status website for development related changes.

Have you tried Google Chrome recently?

Google

Latest Chrome 125 security update fixes 11 unique issues

Posted on May 31, 2024May 31, 2024 by Martin Brinkmann

Google has released a new security update for its Chrome web browser for all supported platforms. The update patches 11 unique security issues in the browser. It comes days after an out-of-bounds security update for Chrome to address a 0-day security vulnerability.

While the issues do not appear to be exploited at the time of writing, it is recommended to update Chrome immediately.

This is done by loading chrome://settings/help in the browser’s address bar or selecting Menu > Help > About Google Chrome manually.

Chrome lists the installed version and will download a new version that it finds automatically on desktop systems.

Pro Tip: open a command prompt window on Windows and run winget upgrade google.chrome.exe to update Chrome without opening it.

Chrome should display one of the following versions after installation of the update:

  • Chrome for Mac or Windows: 125.0.6422.141 or 125.0.6422.142
  • Chrome for Linux: 125.0.6422.141
  • Chrome Extended Channel for Mac or Windows: 124.0.6367.243
  • Chrome for Android: 125.0.6422.146 or 125.0.6422.147

The security fixes

Google lists seven of the eleven security issues that it fixed in the Chrome update on the official releases site.

All seven have a severity rating of high. Google does not publish information about security issues that it discovered internally. The severity of the four unmentioned security issues is unknown as a consequence.

Here is what Google reveals about the listed security issues:

  • [$7000][339877165] High CVE-2024-5493: Heap buffer overflow in WebRTC. Reported by Cassidy Kim(@cassidy6564) on 2024-05-11
  • [TBD][338071106] High CVE-2024-5494: Use after free in Dawn. Reported by wgslfuzz on 2024-05-01
  • [TBD][338103465] High CVE-2024-5495: Use after free in Dawn. Reported by wgslfuzz on 2024-05-01
  • [TBD][338929744] High CVE-2024-5496: Use after free in Media Session. Reported by Cassidy Kim(@cassidy6564) on 2024-05-06
  • [TBD][339061099] High CVE-2024-5497: Out of bounds memory access in Keyboard Inputs. Reported by zh1x1an1221 of Ant Group Tianqiong Security Lab on 2024-05-07
  • [TBD][339588211] High CVE-2024-5498: Use after free in Presentation API. Reported by anymous on 2024-05-09
  • [TBD][339877167] High CVE-2024-5499: Out of bounds write in Streams API. Reported by anonymous on 2024-05-11

The security issues affect several components of the browser, including APIs, keyboard inputs, media session, WebRTC, and Dawn. Dawn is an “open-source and cross-platform implementation of the WebGPU standard” according to Google Source.

Chrome

Chrome warning “These extensions may soon no longer be supported”

Posted on May 30, 2024May 30, 2024 by Martin Brinkmann

Google is working on shutting down the old ruleset for Chrome browser extensions in favor of a new ruleset. The switch from Manifest V2 to Manifest V3 brings along with it a huge problem: extensions that are not updated will cease to work.

While no one has counted the extensions that rely on Manifest V2 in the Chrome Web Store, the count is likely in the thousands. Not all of the are actively maintained.

In addition, some extensions cannot be upgraded without loss of functionality. This is especially the case for content blockers.

Google, an advertising company first and foremost, does have a vetted interest in limiting content blockers. While there is no evidence that the company has made the decision to limit content blockers deliberately, it is clear that content blockers suffer under Manifest V3.

Chrome These extensions may soon no longer be supported

Soon, Chrome is warning users who have extensions installed that rely on Manifest V2. The browser lists extensions that won’t be supported by Chrome in the near future on the extensions page.

Google suggests to either remove the extensions entirely or to replace them with extensions from the Chrome Web Store that support Manifest V3.

Popular extensions such as uBlock Origin and even some of Google’s own are listed there as incompatible.

While there is a chance that some of these extensions will be updated to support Manifest V3, users of Chrome should not get their hopes up that this is the case for all extensions currently incompatible.

If you use Chrome, you can enable the deprecation warning right now in Chrome Canary.

  1. Load chrome://flags/#extension-manifest-v2-deprecation-warning in the Chrome address bar.
  2. Change the state to Enabled.
  3. Restart Google Chrome.
  4. Load chrome://extensions to see the list of unsupported extensions.

Google has revealed the following information about the deprecation of Manifest V2:

  • June 2024 — Manifest V2 extensions will be disabled in pre-stable versions of Chrome starting in Chrome 127. Manifest V2 extensions cannot be installed in Chrome anymore. Google will roll out the change gradually.
  • July 2024 or later — After monitoring the deprecation for at least a month, Google will roll out the deprecation to stable versions of Google Chrome.
  • June 2025 — Manifest V2 extensions cannot be installed anymore on Enterprise devices running Chrome.

The change will impact most Chromium-based browsers as well.

What about your extensions? Are some of them only available as Manifest V2 extensions?

Google fixes another 0-day exploit in Google Chrome

Posted on May 24, 2024May 24, 2024 by Martin Brinkmann

Google has released quite a few security updates for its Chrome web browser in recent months. Besides the weekly scheduled security updates, Google has released updates to address 0-day vulnerabilities in Chrome.

Today, Google released another security update for Google Chrome to address a 0-day exploit. The issue affects all desktop versions of Chrome and Chrome for Android.

Chrome users may want to install the update immediately to fix the issue. Here is how that is done on desktop systems (there is no option to speed up the installation of Chrome updates on Android):

  • Load chrome://settings/help in the Chrome address bar.
  • Chrome displays the current version and runs a check for updates.

Updates will get installed automatically at this point, but you need to restart the browser manually to complete the update.

Chrome should return the following version after installation of the update:

  • Chrome for Windows and Mac: 125.0.6422.112 or 125.0.6422.113
  • Chrome Extended Stable for Windows or Mac: 124.0.6367.233
  • Chrome for Linux: 125.0.6422.112
  • Chrome for Android: 125.0.6422.112 or 125.0.6422.113

About the Chrome security vulnerability

The official release notes page lists basic information about the vulnerability only. It is CVE-2024-5274, a Type Confusion in V8 issue. Google has rated the vulnerability as high and notes that it is exploited in the wild.

V8 is the JavaScript and WebAssembly engine that Google Chrome uses.

In other words, systems with an outdated version of Chrome may be successfully attacked. It is unclear how the issue can be exploited, however.

The last update that fixed a 0-day vulnerability in Google Chrome was released just 2 weeks ago. It is the 8th 0-day exploit fix in Chrome in this year alone.

Enable Device Bound Session Credentials in Google Chrome

Posted on May 16, 2024May 16, 2024 by Martin Brinkmann

Google is working on removing support for third-party cookies in Google Chrome. Cookies continue to be of use, for instance to save preference or as session cookies.

In an effort to make cookies more resilient to attacks, especially stealing, Google started to integrate Device Bound Session Credentials into Chromium.

The main idea here is to bind cookies to a specific device so that attackers who steal it cannot use them.

One of the main threats of cookie stealing is that malware actors may access accounts online without authentication.

Google explains how the feature works:

By binding authentication sessions to the device, DBSC aims to disrupt the cookie theft industry since exfiltrating these cookies will no longer have any value. We think this will substantially reduce the success rate of cookie theft malware. Attackers would be forced to act locally on the device, which makes on-device detection and cleanup more effective, both for anti-virus software as well as for enterprise managed devices.

Note: the feature is still in a prototype stage in Chrome. Google said in April 2024 that it is experimenting with protecting Google accounts in Chrome Beta currently.

How to enable Device Bound Session Credentials in Chrome

Chrome Device Bound Session Credentials

Google Chrome users may enable the feature in their browser already. It is an experimental feature at this stage, which means that it needs to be enabled separately.

Device Bound Session Credentials

Enables Google session credentials binding to cryptographic keys that are practically impossible to extract from the user device. This will mostly prevent the usage of bound credentials outside of the user device. – Mac, Windows, Linux

Here is how that is done:

  1. Load chrome://flags/#enable-bound-session-credentials in the browser’s address bar.
  2. Change the status of the flag to enabled.
  3. Restart Google Chrome.

The security feature is enabled automatically at this point. You can revert the change at any time by changing the status to Default.

  • Previous
  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • Next

Support This Site

If you like what I do please support me!

Any tip is appreciated. Thanks!
  • August 29, 2026 by Martin Brinkmann Another Windows Issue: Microsoft Defender Antivirus is turned off notification, but it is actually enabled
  • August 28, 2026 by Martin Brinkmann Brave Accounts and Email Aliases launch
  • August 25, 2026 by Martin Brinkmann Microsoft confirms: Latest .NET updates may cause printing issues
  • August 24, 2026 by Martin Brinkmann The Chrome Web Store has a fake VPN extensions problem
  • August 23, 2026 by Martin Brinkmann Microsoft is worsening classic Media Player to get users to upgrade

About

We talk, write and dream about Technology 24/7 here at Chipp.in. The site, created by Martin Brinkmann in 2023, focuses on well-researched tech news, reviews, guides, help and more.

Legal Notice

Our commitment

Many websites write about tech, but chipp.in is special in several ways. All of our guides are unique, and we will never just rehash news that you find elsewhere.

Read the About page for additional information on the site and its founder and author.

Support Us

We don't run advertisement on this site that tracks users. If you see ads, they are static links. Ads, including affiliate links, never affect our writing on this site.

Here is a link to our privacy policy

©2026 Chipp.in Tech News and Reviews