X
Business

Google Chrome update doesn't remove older, vulnerable version

When you receive an update, you naturally expect that update to remove old code from your system, especially where that code is vulnerable.It seems that the latest release of Google Chrome broke this simple rule.
Written by Adrian Kingsley-Hughes, Senior Contributing Editor

When you receive an update, you naturally expect that update to remove old code from your system, especially where that code is vulnerable.It seems that the latest release of Google Chrome broke this simple rule.

The latest Google Chrome 3.0.195.24 update plugs up a vulnerability that allowed attackers to run code within the browser's sandbox. However, installing the latest update keeps the old code on the system.

01-10-2009-15-46-22.jpg

I've duplicated this behavior on Windows XP, Vista and 7 systems. Seems like Google needs to roll out another update to fix this problem.

(Thanks to F-Secure for the heads-up)

Editorial standards