<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>gHacks technology news &#187; google chrome vulnerability</title>
	<atom:link href="http://www.ghacks.net/tag/google-chrome-vulnerability/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.ghacks.net</link>
	<description>A technology blog covering software, mobile phones, gadgets, security, the Internet and other relevant areas.</description>
	<lastBuildDate>Tue, 10 Nov 2009 01:33:24 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.5</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Google Chrome Address Spoofing Vulnerability</title>
		<link>http://www.ghacks.net/2008/10/28/google-chrome-address-spoofing-vulnerability/</link>
		<comments>http://www.ghacks.net/2008/10/28/google-chrome-address-spoofing-vulnerability/#comments</comments>
		<pubDate>Tue, 28 Oct 2008 10:16:41 +0000</pubDate>
		<dc:creator>Martin</dc:creator>
				<category><![CDATA[Browsing]]></category>
		<category><![CDATA[Google Chrome]]></category>
		<category><![CDATA[chrome nightly builds]]></category>
		<category><![CDATA[chrome vulnerability]]></category>
		<category><![CDATA[chromium]]></category>
		<category><![CDATA[google chrome]]></category>
		<category><![CDATA[google chrome browser]]></category>
		<category><![CDATA[google chrome vulnerability]]></category>

		<guid isPermaLink="false">http://www.ghacks.net/?p=7916</guid>
		<description><![CDATA[Are that many security vulnerabilities of Google Chrome coming to light because it is less secure than other web browsers? Or is it because everyone is putting more effort into discovering vulnerabilities because it is Google&#8217;s browser? Whatever it is; No week passes by without the discovery of a new security vulnerability in Google Chrome.
The [...]]]></description>
			<content:encoded><![CDATA[<p>Are that many security vulnerabilities of Google Chrome coming to light because it is less secure than other web browsers? Or is it because everyone is putting more effort into discovering vulnerabilities because it is Google&#8217;s browser? Whatever it is; No week passes by without the discovery of a new security vulnerability in Google Chrome.</p>
<p>The latest security vulnerability was discovered by researcher Liu Die Yu of the TopsecTianRongXin research lab in Beijing who discovered a way to spoof the address that is shown in the browser&#8217;s address bar. His proof of concept demonstration makes use of a button and Javascript. A user pressing the button will see an url change in the browser&#8217;s address bar. A look in the source code however reveals that the user is still on the same site and not at the website shown in the address bar.</p>
<p>The flaw could be used to display a PayPal button (or Google Checkout) on a website that would lead to a fake website where the user&#8217;s login credentials could be easily fished. </p>
<p><span id="more-7916"></span>Google will release an end user update soon that will fix the security vulnerability. The only safe thing to do until then is to either switch to Dev Channel builds for the time being that already have a fix included or stop using Google Chrome until the security vulnerability has been patched.</p>
<p>One could think that other browsers based on Webkit are vulnerable as well. This is not the case however according to Liu Die Yu who attributed the security vulnerability to code added by Google developers.</p>

	Tags: <a href="http://www.ghacks.net/tag/chrome-nightly-builds/" title="chrome nightly builds" rel="tag">chrome nightly builds</a>, <a href="http://www.ghacks.net/tag/chrome-vulnerability/" title="chrome vulnerability" rel="tag">chrome vulnerability</a>, <a href="http://www.ghacks.net/tag/chromium/" title="chromium" rel="tag">chromium</a>, <a href="http://www.ghacks.net/tag/google-chrome/" title="google chrome" rel="tag">google chrome</a>, <a href="http://www.ghacks.net/tag/google-chrome-browser/" title="google chrome browser" rel="tag">google chrome browser</a>, <a href="http://www.ghacks.net/tag/google-chrome-vulnerability/" title="google chrome vulnerability" rel="tag">google chrome vulnerability</a><br />

	<h4>Related posts</h4>
	<ul class="st-related-posts">
	<li><a href="http://www.ghacks.net/2008/09/07/google-chrome-nightly-builds-downloader/" title="Google Chrome Nightly Builds Downloader (September 7, 2008)">Google Chrome Nightly Builds Downloader</a> (8)</li>
	<li><a href="http://www.ghacks.net/2009/01/10/google-chrome-20-pre-beta-release/" title="Google Chrome 2.0 Pre-Beta Release (January 10, 2009)">Google Chrome 2.0 Pre-Beta Release</a> (7)</li>
	<li><a href="http://www.ghacks.net/2008/10/23/share-bookmarks/" title="Share Bookmarks (October 23, 2008)">Share Bookmarks</a> (0)</li>
	<li><a href="http://www.ghacks.net/2009/05/14/one-step-closer-to-extension-support-in-google-browser/" title="One Step Closer To Extension Support In Google Browser (May 14, 2009)">One Step Closer To Extension Support In Google Browser</a> (2)</li>
	<li><a href="http://www.ghacks.net/2009/11/04/google-chrome-to-get-automatic-userscript-support/" title="Google Chrome To Get Automatic Userscript Support (November 4, 2009)">Google Chrome To Get Automatic Userscript Support</a> (2)</li>
</ul>

]]></content:encoded>
			<wfw:commentRss>http://www.ghacks.net/2008/10/28/google-chrome-address-spoofing-vulnerability/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Google Chrome Security Vulnerability</title>
		<link>http://www.ghacks.net/2008/09/03/google-chrome-security-vulnerability/</link>
		<comments>http://www.ghacks.net/2008/09/03/google-chrome-security-vulnerability/#comments</comments>
		<pubDate>Wed, 03 Sep 2008 21:41:19 +0000</pubDate>
		<dc:creator>Martin</dc:creator>
				<category><![CDATA[Browsing]]></category>
		<category><![CDATA[Google Chrome]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[google browser]]></category>
		<category><![CDATA[google chrome]]></category>
		<category><![CDATA[google chrome security vulnerability]]></category>
		<category><![CDATA[google chrome vulnerability]]></category>
		<category><![CDATA[google security]]></category>
		<category><![CDATA[security vulnerability]]></category>

		<guid isPermaLink="false">http://www.ghacks.net/?p=6748</guid>
		<description><![CDATA[Now this did not take long. Only one day after releasing a first public beta version of Google Chrome researchers at Kaspersky discovered (Thanks Neil for sending the tip) a security vulnerability that combines a security flaw in Webkit, the browser engine used by Google Chrome, with a Java bug. Apple fixed the vulnerability in [...]]]></description>
			<content:encoded><![CDATA[<p>Now this did not take long. Only one day after releasing a first public beta version of Google Chrome researchers at Kaspersky <a href="http://www.readwriteweb.com/archives/security_flaw_in_google_chrome.php">discovered</a> (Thanks Neil for sending the tip) a security vulnerability that combines a security flaw in Webkit, the browser engine used by Google Chrome, with a Java bug. Apple fixed the vulnerability in Safari back in July after two months of doing nothing about it and it will be interesting to see how fast Google will react to the security vulnerability.</p>
<p>The reason why this vulnerability is still working in Google Chrome is because Google has been using an older version of Webkit for their browser&#8217;s core. First of all, users without Java on their computers are completely safe. Users with Java and Chrome installed should read on.</p>
<p>The problem is serious but requires the user&#8217;s action to be triggered. If the user clicks on a specifically prepared download the file downloads and executes itself automatically without further user input.</p>
<p><span id="more-6748"></span>Security expert Aviv Raff has setup a demo website that demonstrates the vulnerability in Google Chrome. The demonstration page provides a download button which will download and execute a Java file immediately without further user interaction. This demo only opens a notepad application but serious harm could be done with such an exploit.</p>

	Tags: <a href="http://www.ghacks.net/tag/google-browser/" title="google browser" rel="tag">google browser</a>, <a href="http://www.ghacks.net/tag/google-chrome/" title="google chrome" rel="tag">google chrome</a>, <a href="http://www.ghacks.net/tag/google-chrome-security-vulnerability/" title="google chrome security vulnerability" rel="tag">google chrome security vulnerability</a>, <a href="http://www.ghacks.net/tag/google-chrome-vulnerability/" title="google chrome vulnerability" rel="tag">google chrome vulnerability</a>, <a href="http://www.ghacks.net/tag/google-security/" title="google security" rel="tag">google security</a>, <a href="http://www.ghacks.net/tag/security-vulnerability/" title="security vulnerability" rel="tag">security vulnerability</a><br />

	<h4>Related posts</h4>
	<ul class="st-related-posts">
	<li><a href="http://www.ghacks.net/2009/07/10/why-google-chrome-os-will-have-no-huge-impact/" title="Why Google Chrome OS Will Have No Huge Impact (July 10, 2009)">Why Google Chrome OS Will Have No Huge Impact</a> (20)</li>
	<li><a href="http://www.ghacks.net/2009/09/23/who-the-hell-needs-google-chrome-frame/" title="Who The Hell Needs Google Chrome Frame? (September 23, 2009)">Who The Hell Needs Google Chrome Frame?</a> (11)</li>
	<li><a href="http://www.ghacks.net/2009/06/21/web-browser-memory-usage-benchmark-gets-it-all-wrong/" title="Web Browser Memory Usage Benchmark Gets It All Wrong (June 21, 2009)">Web Browser Memory Usage Benchmark Gets It All Wrong</a> (15)</li>
	<li><a href="http://www.ghacks.net/2009/10/17/ten-great-google-chrome-themes/" title="Ten Great Google Chrome Themes (October 17, 2009)">Ten Great Google Chrome Themes</a> (16)</li>
	<li><a href="http://www.ghacks.net/2009/08/23/sync-google-chrome-bookmarks-with-xmarks/" title="Sync Google Chrome Bookmarks With Xmarks (August 23, 2009)">Sync Google Chrome Bookmarks With Xmarks</a> (0)</li>
</ul>

]]></content:encoded>
			<wfw:commentRss>http://www.ghacks.net/2008/09/03/google-chrome-security-vulnerability/feed/</wfw:commentRss>
		<slash:comments>21</slash:comments>
		</item>
	</channel>
</rss>
