Adobe Flash fix drags Google into Microsoft's Patch Tuesday

Google has been dragged into adopting rival Microsoft's Patch Tuesday, following a move from Adobe last month.


Google has been dragged into adopting rival Microsoft's Patch Tuesday, following a move from Adobe last month.

Earlier this week, Google updated its Chrome browser, quashing six bugs and as it often does, also updating Adobe's Flash Player. That same day, Microsoft shipped seven security updates to patch 12 vulnerabilities, and Adobe released a new version of Flash to address three critical bugs.

It was the Flash patches that triggered Chrome's copycat update: In November, Adobe announced it would synchronise Flash updates with long-time-partner Microsoft's Patch Tuesday. Most security experts applauded the decision, which they said was prompted by the bundling of Flash with Internet Explorer 10 (IE10) on Windows 8 and Windows RT.

Those same experts said Adobe's hand was probably forced by Microsoft, which had caused problems this when it failed to sync IE10 updates with those shipped by Adobe for Flash.

But because Google also bakes Flash Player into Chrome, Adobe's Patch Tuesday adoption also requires Google to ship updates the same day or put its users at risk.

Chrome has included Flash since April 2010, and is regularly updated whenever Adobe patches the popular media player.

Security professionals praised the three-vendor synchronisation on the month's most important patch day.

"We already knew that Microsoft was the leader in security patch cadence, so for others to fall in line was inevitable," said Andrew Storms, director of security operations, in an instant message interview. "I suspect the more this happens, the more vendors will want to coordinate. It really is better for both them and customers if everyone knows a patch is imminent."

Jason Miller, manager of research and development at VMware, concurred. "It's good to see vendors coordinate like this," he said in an interview earlier this week.

But even more could be done.

"The biggest win [for users] is if all the vendors provided an advance notification so security teams could plan accordingly," he said. "Without proper notice, we are really in the same boat as before, where the surprise updates catch you off guard."

Adobe does not offer pre-patch notifications for Flash -- it does for Adobe Reader and Acrobat, however -- and neither does Google for Chrome.

Although Google patched Chrome on Tuesday -- and also on last month's Patch Tuesday of Nov. 13 -- it does not hew to a Patch Tuesday-only schedule, as Microsoft and Adobe do for all but emergency updates. Typically, Chrome is patched several times each month, on no set schedule. In the month between the last two Patch Tuesdays, for instance, Google updated Chrome twice.

The six Chrome patches Google provided Dec. 11 included three reported by independent researchers, who were awarded a total of $4,500 in bounty payments. So far this year, Google has paid more than $380,000 in Chrome bounties.

Chrome is automatically updated in the background each time Google patches the browser. The newest version can also be downloaded from Google's website for Windows, OS X and Linux.

"Recommended For You"

Patch Tuesday to fix first Windows 8 critical flaws Microsoft patches critical flaws in Windows 8, Windows RT