Vulnerability Exposed in Google Chrome Beta
Every piece of software on the planet is subject to its share of bugs and flaws at some point in time. It is part of human nature to make mistakes, in this situation it is in the lines of software code. Equally, Internet Explorer, Mozilla and Safari have seen their fair share of interesting ‘features’. It is only expected to see the same thing happen with Chrome, Hence the reason why it is in public Beta stages at this point.
A few hours after the launch of the Chrome public Beta, security researcher Aviv Raff found a hole in the new browser. The new found flaw targets an older version of the WebKit rendering engine. Apple’s latest Safari release uses a newer version of WebKit which is immune from this specific flaw, however Chrome does not.
Aviv Raff has publicized a ‘proof-of-concept’ demonstration showcasing this vulnerability. The demonstration causes Firefox to prompt its users of a Java JAR file download. In Chrome, the file is automatically downloaded without any prompting to the users desktop. Malicious programmers with some good con-artist skills could easily use this vulnerability to trick users in to executing the Java application. The possibilities with what the Java does are endless at this point, just use your imagination.
Raff’s demonstration uses a simple Java based text editing application. You can view the demonstration here.
ZDNet also mentioned that this vulnerability could be used to execute a ‘combo attack’ through an un-patched Internet Explorer flaw. Raff had already spoke of this flaw in relation to Safari back in the last quarter of May. He has not yet released the details, however.
- Microsoft Aims Windows 7 to Boot in 15 Seconds
- Samsung: Blu-ray Has Five Years Left, OLED the Next Big Thing
- AMD, Nvidia Conspire to Price Fixing; Sued
- Dell Launching Inspiron 910 Mini Notebook Thursday
- Blu-ray Drives Hit 8X Write Speeds
- Nvidia Expanding for Intel Core i7
- Report: 88 Percent of IT Workers Would Steal Data If Fired
- Intel Adds 3 New Value CPUs
- Meet IE8: Resource Pig
- Sony Debuts Three All-In-One Desktop PCs With Blu-ray
- PNY and Sony To Release Movies On USB Flash Drives
- Sony VAIO Users Get Burned, Sony Recalls 440,000 units
- Gaming Consoles a Goldmine for More Than Just Games
- Six-Core Intel Xeon 7400 Shipping September 15
- Guy Makes a PC Out of Nintendo Wii
- Microsoft Doubles Storage Capacity For Netbooks
- TiVo's New HD XL DVR Could Save Your Marriage
- Microsoft to Also Rock September 9 With New Gadgets





Chrome doesn't install behind a proxy, it doesn't stay installed on my vista machine connected to a network. Has anyone seen where it installs? C:\users\*username*\appdata\....
Ridiculous.
Seems like a reasonably nice browser though, and I love the amount of webpage you can actually see.