Google Chrome Security Vulnerability

Status
Not open for further replies.

Osiris

Golden Master
Messages
36,817
Location
Kentucky
Google Chrome Security Vulnerability

Now this did not take long. Only one day after releasing a first public beta version of Google Chrome researchers at Kaspersky discovered (Thanks Neil for sending the tip) a security vulnerability that combines a security flaw in Webkit, the browser engine used by Google Chrome, with a Java bug. Apple fixed the vulnerability in Safari back in July after two months of doing nothing about it and it will be interesting to see how fast Google will react to the security vulnerability.
The reason why this vulnerability is still working in Google Chrome is because Google has been using an older version of Webkit for their browser's core. First of all, users without Java on their computers are completely safe. Users with Java and Chrome installed should read on.
The problem is serious but requires the user's action to be triggered. If the user clicks on a specifically prepared download the file downloads and executes itself automatically without further user input.
Security expert Aviv Raff has setup a demo website that demonstrates the vulnerability in Google Chrome. The demonstration page provides a download button which will download and execute a Java file immediately without further user interaction. This demo only opens a notepad application but serious harm could be done with such an exploit.
 
... What the... its only a day... oww for Google.. (so is anybody here using it)
 
Lol wow...interesting.
Nope, I don't have it yet, Vern. Good thing probably, too lol. I'm gonna wait till a final release, personally.
 
I was using it. Still will. This was known from the get go. They reported it less than 2 hours after it was released. Kaspersky and them are slow. I read about this yesterday. Still didnt scare me away from using it.
 
its a beta and I'm sure they'll fix it quickly. I'm pretty sure Vista vulnerabilities were found in the first week, and not the Beta the real release, one reason why I try not to use beta software a lot.
 
Status
Not open for further replies.
Back
Top Bottom