Advertisement
Promo

Security threats Toolkit

Google Chrome

Security firm discovers Chrome 'SaveAs' flaw

Jonathan Skillings CNET News

Published: 08 Sep 2008 09:19 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

A company in Vietnam has turned up the latest vulnerability in Chrome, according to a story posted to Information Week's website.

Bach Khoa Internet Security says the Chrome 0.2.149.27 release is susceptible to a critical buffer-overflow flaw, which could allow a remote attacker to take control of a PC. BKIS says it has reported the vulnerability to Google.

BKIS explained the security flaw: "The vulnerability is caused due to a boundary error when handling the 'SaveAs[ function. On saving a malicious page with an overly long title (title tag in HTML), the program causes a stack-based overflow and makes it possible for attackers to execute arbitrary code on users' systems.

Read this

Roundup
Roundup: Countdown to Google Chrome

Google's open-source browser sends a clear challenge to Microsoft...

Read more +

The security company described how the flaw could be exploited: "A hacker might construct a specially crafted web page, which contains malicious code. He then tricks users into visiting his website and convinces them to save this page. Right after that, the code would be executed, giving him the privilege to make use of the affected system. "

Earlier this week, security researcher Rishi Narang reported a flaw related to how Chrome, still in beta, behaves with undefined handlers, while another researcher, Aviv Raff, developed a proof-of-concept demo that showed Chrome could be hit with a carpet-bombing flaw.

For full coverage of the Google Chrome launch, see ZDNet.co.uk's roundup.

Credit: Security firm spots Chrome 'SaveAs' flaw from CNET News

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
6 out of 6 people found this useful


Full Talkback thread

1 comment

  1. Chrome needs more work 1000215420

More in this Special Report

Roundup: Full coverage of Google Chrome

Roundup: Full coverage of Google Chrome

The search giant's launch of its own open-source browser sends a clear challenge to Microsoft more

Google announces Chrome operating system

Google announces Chrome operating system

The Google Chrome Operating System project aims to build a Linux-based OS available for purchase on netbooks in the second half of 2010 more

Blog: Google Chrome — nine things we've found since launch

Blog: Google Chrome — nine things we've found since launch

Google must be very happy with the coverage Chrome has gathered. But it's not all good news... more

Photos: Highlights of the beta browser

Photos: Highlights of the beta browser

For years, people have speculated about whether Google would ever release its own operating system. And now, it has — in a way... more

Leader: Chrome needs more than just sparkle

Leader: Chrome needs more than just sparkle

There's a lot of technology in Google's Chrome browser. Its success depends on something more more

Can Chrome shine amid the competition?

Can Chrome shine amid the competition?

ZDNet.com's Sumi Das reports on why Google has jumped into the browser fray, and explores the company's hopes for Chrome more

Benchmarks: Google Chrome

Benchmarks: Google Chrome

Google's Chrome browser seeks to set new speed standards and thus accelerate the development of AJAX-based web applications. Check out our comparative performance test to see how it fares more

Review: Google Chrome (beta)

Review: Google Chrome (beta)

Google has launched Chrome, an open-source browser that sends a clear challenge to Microsoft in the way it lets users work with applications more

Video: Google Chrome to open new front in browser war

Video: Google Chrome to open new front in browser war

On Tuesday evening, Google will release a beta of its Chrome browser. Rupert Goodwins looks forward to the latest campaign in the browser war more

Comment: All roads lead to Chrome

Comment: All roads lead to Chrome

With its new browser, Google has finally taken its gaudy, chrome-plated, futuristic ray gun and pointed it straight at Microsoft's head more

Blog: Google Chrome has Microsoft's code inside, says MS manager

Blog: Google Chrome has Microsoft's code inside, says MS manager

And furthermore, he says, that's a good thing... more

Company/Topic Alerts

Create a new alert from the list below:




Video icon

Video

Sentry Posts Blog

Motorola Droid Drops Today: Happy Droi...

Motorola Droid Drops Today: Happy Droid Day America! Author: Eric Everson, Mobile Security Expert If you’re wondering what all of the buzz is about with words like Droid and Android... More

Post a comment

Mobile Security Profile: BlackBerry St...

Mobile Security Profile: BlackBerry Storm2 Author: Eric Everson BlackBerry handsets are a staple of office culture; from syncing calendars to sharing business-related data,... More

Post a comment

South Korea plans to fingerprint visit...

The South Korean authorities could fingerprint and photograph foreign visitors from 2012, the Korea Times reported on Tuesday. Barring diplomats and government operatives, all visitors... More

Post a comment


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters