search technology reviews, news, features, group tests
Popular Searches:   video , dell , dvd
 |  Register
 |  Newsletters  | 
Sitemap  |  RSS
RSS
Monday November 23, 2009 12:53 PM AEST
Skip Navigation LinksPC Authority > News > Security world makes short work of Chrome
Security world makes short work of Chrome
NEWS

Security world makes short work of Chrome

by Shaun Nichols  on Sep 4, 2008
Tags: Security | world | makes | short | work | of | Chrome
Google browser open to 'carpet bomb' attack, other flaws.
Less than two days into its public life, Google's Chrome browser is being put under the microscope by security researchers.

Two flaws for the web browser have already been discovered and publically disclosed by researchers. Ramifications of an attack could range from an application crash to remote malware installation.

The first vulnerability was found on Wednesday by researcher Aviv Raff, who discovered that the browser was open to a highly-publicized 'carpet bombing' attack first found in Safari.

Apple patched the flaw in Safari earlier this year. However, because Chrome uses Apple's WebKit software, the flaw has reappeared in the Google browser.

Raff posted a proof of concept page which demonstrates how an attacker could embed malicious code on a web page and then use it to conduct a remote malware installation with a separate specially-crafted Java applet.

Shortly after Raff's discovery was posted, another researcher came forward with a separate flaw in the browser.

Researchers Rishi Narang and JanDeMooij posted separate reports of a vulnerability in the browser's chromium.dll component that was exposed through the browser's URL bar. The flaw could be targeted to cause an application crash, though neither report mentioned the possibility of remote code execution.

Chrome is not the first browser to be picked apart by the security community so soon. Researchers made similarly short work out of Mozilla's Firefox 3 when that browser was released earlier this summer.

Copyright © 2009 v3.co.uk
Email a Friend Email this
Print Page Print this
Tweet This Tweet this
Feedback Send us your tips


Ads by Google

Comments

Be the first to comment on this article.
Thoughts on this article? Add a comment below.
Login or register to submit a comment.
 

Top Stories

Telstra confirm 30Mbit national network plan - but don't mention the NBN
Telstra has completed the 100Mbit upgrade to their Melbourne cable network and are next planning to get 30Mbit speeds into the rest of the country; but first they'll need to dispel those endless NBN comparisons
 
Red Hat updates with Fedora 12
Red Hat has released the latest version of its Fedora open source operating system and has added new video, virtualisation and networking support..
 
Picking the perfect home entertainment box: Movie downloads come to the Xbox 360
Unmetered download agreements are next the battleground as games consoles follow the Apple TV's lead to support movie download services.
 


 
Intel
 
 
LogMeIn
 
 
Amazing Dell Coupons now available
 
Discover Apple