Google Chrome vulnerable to carpet-bombing flaw
Summary: Google's shiny new Web browser is vulnerable to a carpet-bombing vulnerability that could expose Windows users to malicious hacker attacks.Just hours after the release of Google Chrome, researcher Aviv Raff discovered that he could combine two vulnerabilities -- a flaw in Apple Safari (WebKit) and a Java bug discussed at this year's Black Hat conference -- to trick users into launching executables direct from the new browser.
Google's shiny new Web browser is vulnerable to a carpet-bombing vulnerability that could expose Windows users to malicious hacker attacks.
Just hours after the release of Google Chrome, researcher Aviv Raff discovered that he could combine two vulnerabilities -- a flaw in Apple Safari (WebKit) and a Java bug discussed at this year's Black Hat conference -- to trick users into launching executables direct from the new browser.
Raff has cooked up a harmless demo of the attack in action, showing how a Google Chrome users can be lured into downloading and launching a JAR (Java Archive) file that gets executed without warning.
[ SEE: Google Chrome, the security tidbits ]
In the proof-of-concept, Raff's code shows how a malicious hacker can use a clever social engineering lure -- it requires two mouse clicks -- to plant malware on Windows desktops.
The Google Chrome user-agent shows that Chrome is actually WebKit 525.13 (Safari 3.1), which is an outdated/vulnerable version of that browser.
Apple patched the carpet-bombing issue with Safari v3.1.2.
Some Google Chrome early adopters using Windows Vista are reporting that files downloaded from the Internet are automatically dropped on the desktop, setting up a scenario where a combo-attack using this unpatched IE flaw could be used in attacks.
Kick off your day with ZDNet's daily email newsletter. It's the freshest tech news and opinion, served hot. Get it.
Talkback
just proves that no software can ever be without any flaws
Especially when its built...
Why would Apple tell them?
No one except Google
Sure, Apple's original software had the flaw, but given that this was s KNOWN flaw, once Google modified it and slapped its name on it Apple's responsibility ended.
wow. pathetic, just pathetic
Yep. Pretty lame.
Duh.
Give me a break! It's a BETA...
As usaual...
I still know alot of forums, shouting at the bugs in the IE8 beta release. At that time, there was no one to think that [b]IE is in BETA state[/b].
Anyway, choices & opinions are personal. It will be much better, if u watch your back at the time of commenting.
ie8 = beta?
It's an oversight on the version of the software used to build it, not something that's coded into the product.
except WebKit is NOT the compromised code
Apple's decision to automatically download anything with Safari,
which is part of the UI shell, not the webkit engine.
Chrome already has an option to prompt every time before
download, so it's actually NOT vulnerable to this carpet bombing
exploit.
more typical ZDnet FUD
desktop using permissions. R-E-A-S-E-A-R-C-H
Are u sure?
RTFA
OOPS
egg on face
mouth outfitted with shoe store
etc...
In my defense, I read the whole comic, so clearly I am
a Chrome security expert already... there must be
something wrong with the intarweb.
props for a good apology
RE: Google Chrome vulnerable to carpet-bombing flaw
I can do that in one click. Open Internet Explorer.
RE: Google Chrome vulnerable to carpet-bombing flaw
Wait a minute...
It's Microsoft Windows that has the security bug -- check out the link in the article to Microsoft's own page about it. Windows is executing files it shouldn't.
Both of them have a flaw
yes but.....
Technically IE has beta 2, but it's being used
extensively.
What you said...
used? It just came out yesterday. I agree that IE is
being used extensively, but not necessarily the beta.
Unless "extensively" to you is 50,000 people or so.