<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>gHacks technology news &#187; chrome vulnerability</title>
	<atom:link href="http://www.ghacks.net/tag/chrome-vulnerability/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.ghacks.net</link>
	<description>A technology blog covering software, mobile phones, gadgets, security, the Internet and other relevant areas.</description>
	<lastBuildDate>Wed, 25 Nov 2009 09:43:02 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.6</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Google Chrome Address Spoofing Vulnerability</title>
		<link>http://www.ghacks.net/2008/10/28/google-chrome-address-spoofing-vulnerability/</link>
		<comments>http://www.ghacks.net/2008/10/28/google-chrome-address-spoofing-vulnerability/#comments</comments>
		<pubDate>Tue, 28 Oct 2008 10:16:41 +0000</pubDate>
		<dc:creator>Martin</dc:creator>
				<category><![CDATA[Browsing]]></category>
		<category><![CDATA[Google Chrome]]></category>
		<category><![CDATA[chrome nightly builds]]></category>
		<category><![CDATA[chrome vulnerability]]></category>
		<category><![CDATA[chromium]]></category>
		<category><![CDATA[google chrome]]></category>
		<category><![CDATA[google chrome browser]]></category>
		<category><![CDATA[google chrome vulnerability]]></category>

		<guid isPermaLink="false">http://www.ghacks.net/?p=7916</guid>
		<description><![CDATA[Are that many security vulnerabilities of Google Chrome coming to light because it is less secure than other web browsers? Or is it because everyone is putting more effort into discovering vulnerabilities because it is Google&#8217;s browser? Whatever it is; No week passes by without the discovery of a new security vulnerability in Google Chrome.
The [...]]]></description>
			<content:encoded><![CDATA[<p>Are that many security vulnerabilities of Google Chrome coming to light because it is less secure than other web browsers? Or is it because everyone is putting more effort into discovering vulnerabilities because it is Google&#8217;s browser? Whatever it is; No week passes by without the discovery of a new security vulnerability in Google Chrome.</p>
<p>The latest security vulnerability was discovered by researcher Liu Die Yu of the TopsecTianRongXin research lab in Beijing who discovered a way to spoof the address that is shown in the browser&#8217;s address bar. His proof of concept demonstration makes use of a button and Javascript. A user pressing the button will see an url change in the browser&#8217;s address bar. A look in the source code however reveals that the user is still on the same site and not at the website shown in the address bar.</p>
<p>The flaw could be used to display a PayPal button (or Google Checkout) on a website that would lead to a fake website where the user&#8217;s login credentials could be easily fished. </p>
<p><span id="more-7916"></span>Google will release an end user update soon that will fix the security vulnerability. The only safe thing to do until then is to either switch to Dev Channel builds for the time being that already have a fix included or stop using Google Chrome until the security vulnerability has been patched.</p>
<p>One could think that other browsers based on Webkit are vulnerable as well. This is not the case however according to Liu Die Yu who attributed the security vulnerability to code added by Google developers.</p>

	Tags: <a href="http://www.ghacks.net/tag/chrome-nightly-builds/" title="chrome nightly builds" rel="tag">chrome nightly builds</a>, <a href="http://www.ghacks.net/tag/chrome-vulnerability/" title="chrome vulnerability" rel="tag">chrome vulnerability</a>, <a href="http://www.ghacks.net/tag/chromium/" title="chromium" rel="tag">chromium</a>, <a href="http://www.ghacks.net/tag/google-chrome/" title="google chrome" rel="tag">google chrome</a>, <a href="http://www.ghacks.net/tag/google-chrome-browser/" title="google chrome browser" rel="tag">google chrome browser</a>, <a href="http://www.ghacks.net/tag/google-chrome-vulnerability/" title="google chrome vulnerability" rel="tag">google chrome vulnerability</a><br />

	<h4>Related posts</h4>
	<ul class="st-related-posts">
	<li><a href="http://www.ghacks.net/2008/09/07/google-chrome-nightly-builds-downloader/" title="Google Chrome Nightly Builds Downloader (September 7, 2008)">Google Chrome Nightly Builds Downloader</a> (8)</li>
	<li><a href="http://www.ghacks.net/2009/01/10/google-chrome-20-pre-beta-release/" title="Google Chrome 2.0 Pre-Beta Release (January 10, 2009)">Google Chrome 2.0 Pre-Beta Release</a> (7)</li>
	<li><a href="http://www.ghacks.net/2008/10/23/share-bookmarks/" title="Share Bookmarks (October 23, 2008)">Share Bookmarks</a> (0)</li>
	<li><a href="http://www.ghacks.net/2009/05/14/one-step-closer-to-extension-support-in-google-browser/" title="One Step Closer To Extension Support In Google Browser (May 14, 2009)">One Step Closer To Extension Support In Google Browser</a> (2)</li>
	<li><a href="http://www.ghacks.net/2009/11/04/google-chrome-to-get-automatic-userscript-support/" title="Google Chrome To Get Automatic Userscript Support (November 4, 2009)">Google Chrome To Get Automatic Userscript Support</a> (2)</li>
</ul>

]]></content:encoded>
			<wfw:commentRss>http://www.ghacks.net/2008/10/28/google-chrome-address-spoofing-vulnerability/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
