Version History of Google Chrome 18.0.1025.151 (Beta)
- Black screen on Hybrid Graphics system with GPU accelerated compositing enabled (Issue: 117371)
- CSS not applied to element (Issue: 114667)
- Regression rendering a div with background gradient and borders (Issue: 113726)
- Canvas 2D line drawing bug with GPU acceleration (Issue: 121285)
- Multiple crashes (Issues: 72235, 116825 and 92998)
- Pop-up dialog is at wrong position (Issue: 116045)
- HTML Canvas patterns are broken if you change the transformation matrix (Issue: 112165)
- SSL interstitial error "proceed anyway" / "back to safety" buttons don't work (Issue: 119252)
- HTML5 audio doesn't work on some Mac computers (Issue: 109441)
Security fixes and rewards:
A new version of Flash Player is included. More details are available in an addendum to this Flash Player advisory.
Please see the Chromium security page for more detail. Note that the referenced bugs may be kept private until a majority of our users are up to date with the fix.
- [$500]  Medium CVE-2011-3066: Out-of-bounds read in Skia clipping. Credit to miaubiz.
-  Medium CVE-2011-3067: Cross-origin iframe replacement. Credit to Sergey Glazunov.
- [$1000]  High CVE-2011-3068: Use-after-free in run-in handling. Credit to miaubiz.
- [$1000]  High CVE-2011-3069: Use-after-free in line box handling. Credit to miaubiz.
-  High CVE-2011-3070: Use-after-free in v8 bindings. Credit to Google Chrome Security Team (SkyLined).
-  High CVE-2011-3071: Use-after-free in HTMLMediaElement. Credit to pa_kt, reporting through HP TippingPoint ZDI (ZDI-CAN-1528).
-  Low CVE-2011-3072: Cross-origin violation parenting pop-up window. Credit to Sergey Glazunov.
- [$1000]  High CVE-2011-3073: Use-after-free in SVG resource handling. Credit to Arthur Gerkis.
- [$500]  Medium CVE-2011-3074: Use-after-free in media handling. Credit to S?awomir B?a?ek.
- [$1000]  High CVE-2011-3075: Use-after-free applying style command. Credit to miaubiz.
- [$1000]  High CVE-2011-3076: Use-after-free in focus handling. Credit to miaubiz.
-  Medium CVE-2011-3077: Read-after-free in script bindings. Credit to Google Chrome Security Team (Inferno).