The first phase of the plan is to disable Flash for ads and "background analytics", with the ultimate goal of disabling it completely by the end of the year, except on specific sites that Google has deemed to be broken without it.Flash would then be re-enabled with the exclusion of ads and background analytics on a site-by-site basis.

This passage was inherited from the general Google terms of service.

The V8 Java Script virtual machine was considered a sufficiently important project to be split off (as was Adobe/Mozilla's Tamarin) and handled by a separate team in Denmark coordinated by Lars Bak at Aarhus.

Google's official response to the exploits was delivered by Jason Kersey, who congratulated the researchers, noting "We also believe that both submissions are works of art and deserve wider sharing and recognition." A significant number of security vulnerabilities in Chrome occur in the Adobe Flash Player.

For example, in the 2016 Pwn2Own successful attack on Chrome relied on four security vulnerabilities.

In 2013, they forked the Web Core component to create their own layout engine Blink.

Based on Web Kit, Blink only uses Web Kit's "Web Core" components, while substituting other components, such as its own multi-process architecture, in place of Web Kit's native implementation.

Chrome is internally tested with unit testing, "automated user interface testing of scripted user actions", fuzz testing, as well as Web Kit's layout tests (99% of which Chrome is claimed to have passed), and against commonly accessed websites inside the Google index within 20–30 minutes.

On January 11, 2011, the Chrome product manager, Mike Jazayeri, announced that Chrome would remove H.264 video codec support for its HTML5 player, citing the desire to bring Google Chrome more in line with the currently available open codecs available in the Chromium project, which Chrome is based on.

In this test, Chrome version 37 scored 10 failed/11578 passed.

