A scheme validation error in WebUI (CVE-2015-1266).
Two cross-origin bypass issues in Blink (CVE-2015-1267, CVE-2015-1268).
A normalization error in the HSTS/HPKP preload list (CVE-2015-1269).
This update also disables the automatic, silent downloading and installation of "external components" like the hotword extension.