Advertisement
Promo

Security threats Toolkit

Google Chrome

Security firm discovers Chrome 'SaveAs' flaw

Jonathan Skillings CNET News

Published: 08 Sep 2008 09:19 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

A company in Vietnam has turned up the latest vulnerability in Chrome, according to a story posted to Information Week's website.

Bach Khoa Internet Security says the Chrome 0.2.149.27 release is susceptible to a critical buffer-overflow flaw, which could allow a remote attacker to take control of a PC. BKIS says it has reported the vulnerability to Google.

BKIS explained the security flaw: "The vulnerability is caused due to a boundary error when handling the 'SaveAs[ function. On saving a malicious page with an overly long title (title tag in HTML), the program causes a stack-based overflow and makes it possible for attackers to execute arbitrary code on users' systems.

Read this

Roundup
Roundup: Countdown to Google Chrome

Google's open-source browser sends a clear challenge to Microsoft...

Read more +

The security company described how the flaw could be exploited: "A hacker might construct a specially crafted web page, which contains malicious code. He then tricks users into visiting his website and convinces them to save this page. Right after that, the code would be executed, giving him the privilege to make use of the affected system. "

Earlier this week, security researcher Rishi Narang reported a flaw related to how Chrome, still in beta, behaves with undefined handlers, while another researcher, Aviv Raff, developed a proof-of-concept demo that showed Chrome could be hit with a carpet-bombing flaw.

For full coverage of the Google Chrome launch, see ZDNet.co.uk's roundup.

Credit: Security firm spots Chrome 'SaveAs' flaw from CNET News

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Did you find this article useful?
6 out of 6 people found this useful


Full Talkback thread

1 comment

  1. Chrome needs more work 1000215420

More in this Special Report

Roundup: Full coverage of Google Chrome

Roundup: Full coverage of Google Chrome

The search giant's launch of its own open-source browser sends a clear challenge to Microsoft more

Google shows Chrome OS, promises 2010 launch

Google shows Chrome OS, promises 2010 launch

Google's long-awaited Chrome OS aims at security, speed and simplicity in netbook cloud computing more

Google announces Chrome operating system

Google announces Chrome operating system

The Google Chrome Operating System project aims to build a Linux-based OS available for purchase on netbooks in the second half of 2010 more

Photos: Highlights of the beta browser

Photos: Highlights of the beta browser

For years, people have speculated about whether Google would ever release its own operating system. And now, it has — in a way... more

Leader: Chrome needs more than just sparkle

Leader: Chrome needs more than just sparkle

There's a lot of technology in Google's Chrome browser. Its success depends on something more more

Can Chrome shine amid the competition?

Can Chrome shine amid the competition?

ZDNet.com's Sumi Das reports on why Google has jumped into the browser fray, and explores the company's hopes for Chrome more

Benchmarks: Google Chrome

Benchmarks: Google Chrome

Google's Chrome browser seeks to set new speed standards and thus accelerate the development of AJAX-based web applications. Check out our comparative performance test to see how it fares more

Review: Google Chrome (beta)

Review: Google Chrome (beta)

Google has launched Chrome, an open-source browser that sends a clear challenge to Microsoft in the way it lets users work with applications more

Video: Google Chrome to open new front in browser war

Video: Google Chrome to open new front in browser war

On Tuesday evening, Google will release a beta of its Chrome browser. Rupert Goodwins looks forward to the latest campaign in the browser war more

Comment: All roads lead to Chrome

Comment: All roads lead to Chrome

With its new browser, Google has finally taken its gaudy, chrome-plated, futuristic ray gun and pointed it straight at Microsoft's head more

Google releases stable version of Chrome 3.0

Google releases stable version of Chrome 3.0

Google has announced that the third stable release of Chrome is ready for the world, a little over a year after its debut more

Video icon

Video

Sentry Posts Blog

Malicious Mobile Apps a Growing Concer...

Malicious Mobile Apps a Growing Concern Author: Eric Everson, MBA, MSIT-SE The phrase “mobile security” does not usually mean much to anyone, until of course they encounter their... More

Post a comment

Malicious Mobile Code: What You Need t...

Malicious Mobile Code: What You Need to Know. Author: Eric Everson, MBA, MSIT-SE The thought of someone hacking into your mobile phone to steal your personal data added to the growing... More

1 comment

Bletchley Park calls for operators for...

The home of World War II codebreaking has called for engineers to operate an electro-mechanical machine developed by mathematician Alan Turing. The Turing Bombe was a brute-force... More

2 comments


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters