The fact that Chrome added incognito window is a good sign, the fact that there is still no flash block is a bad one IMO. Honestly, I think gmail and search are probably more dangerous when it comes to privacy. People can track the information Chrome sends back to Google, but you have no idea what happens once your data is on their servers.
They're adding 'click-to-play' as an option for plugins like flash in the default browser settings (no extension required) in version 18. It's allowed people to turn on the radio button using about:flags for more than a year.
Once enabled, go to wrench menu > Settings > Under the Bonnet > Advanced Settings > Privacy > Content Settings > Plug-ins