<?xml version="1.0" encoding="UTF-8"?> <rss
version="2.0"
xmlns:content="http://purl.org/rss/1.0/modules/content/"
xmlns:wfw="http://wellformedweb.org/CommentAPI/"
xmlns:dc="http://purl.org/dc/elements/1.1/"
xmlns:atom="http://www.w3.org/2005/Atom"
xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
> <channel><title>gHacks Technology News &#124; Latest Tech News, Software And Tutorials &#187; google chrome vulnerability</title> <atom:link href="http://www.ghacks.net/tag/google-chrome-vulnerability/feed/" rel="self" type="application/rss+xml" /><link>http://www.ghacks.net</link> <description>A technology news blog covering software, mobile phones, gadgets, security, the Internet and other relevant areas.</description> <lastBuildDate>Sat, 11 Feb 2012 09:52:46 +0000</lastBuildDate> <language>en</language> <sy:updatePeriod>hourly</sy:updatePeriod> <sy:updateFrequency>1</sy:updateFrequency> <generator>http://wordpress.org/?v=3.3.1</generator> <atom:link rel="hub" href="http://pubsubhubbub.appspot.com"/><atom:link rel="hub" href="http://superfeedr.com/hubbub"/> <item><title>Google Chrome Address Spoofing Vulnerability</title><link>http://www.ghacks.net/2008/10/28/google-chrome-address-spoofing-vulnerability/</link> <comments>http://www.ghacks.net/2008/10/28/google-chrome-address-spoofing-vulnerability/#comments</comments> <pubDate>Tue, 28 Oct 2008 10:16:41 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[Browsing]]></category> <category><![CDATA[Google Chrome]]></category> <category><![CDATA[chrome nightly builds]]></category> <category><![CDATA[chrome vulnerability]]></category> <category><![CDATA[chromium]]></category> <category><![CDATA[google chrome]]></category> <category><![CDATA[google chrome browser]]></category> <category><![CDATA[google chrome vulnerability]]></category> <guid
isPermaLink="false">http://www.ghacks.net/?p=7916</guid> <description><![CDATA[Are that many security vulnerabilities of Google Chrome coming to light because it is less secure than other web browsers? Or is it because everyone is putting more effort into discovering vulnerabilities because it is Google&#8217;s browser? Whatever it is; No week passes by without the discovery of a new security vulnerability in Google Chrome. [...]]]></description> <content:encoded><![CDATA[<p>Are that many security vulnerabilities of Google Chrome coming to light because it is less secure than other web browsers? Or is it because everyone is putting more effort into discovering vulnerabilities because it is Google&#8217;s browser? Whatever it is; No week passes by without the discovery of a new security vulnerability in Google Chrome.</p><p>The latest security vulnerability was discovered by researcher Liu Die Yu of the TopsecTianRongXin research lab in Beijing who discovered a way to spoof the address that is shown in the browser&#8217;s address bar. His proof of concept demonstration makes use of a button and Javascript. A user pressing the button will see an url change in the browser&#8217;s address bar. A look in the source code however reveals that the user is still on the same site and not at the website shown in the address bar.</p><p>The flaw could be used to display a PayPal button (or Google Checkout) on a website that would lead to a fake website where the user&#8217;s login credentials could be easily fished.</p><p><span
id="more-7916"></span>Google will release an end user update soon that will fix the security vulnerability. The only safe thing to do until then is to either switch to Dev Channel builds for the time being that already have a fix included or stop using Google Chrome until the security vulnerability has been patched.</p><p>One could think that other browsers based on Webkit are vulnerable as well. This is not the case however according to Liu Die Yu who attributed the security vulnerability to code added by Google developers.</p> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2008/10/28/google-chrome-address-spoofing-vulnerability/feed/</wfw:commentRss> <slash:comments>0</slash:comments> </item> <item><title>Google Chrome Security Vulnerability</title><link>http://www.ghacks.net/2008/09/03/google-chrome-security-vulnerability/</link> <comments>http://www.ghacks.net/2008/09/03/google-chrome-security-vulnerability/#comments</comments> <pubDate>Wed, 03 Sep 2008 21:41:19 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[Browsing]]></category> <category><![CDATA[Google Chrome]]></category> <category><![CDATA[Security]]></category> <category><![CDATA[google browser]]></category> <category><![CDATA[google chrome]]></category> <category><![CDATA[google chrome security vulnerability]]></category> <category><![CDATA[google chrome vulnerability]]></category> <category><![CDATA[google security]]></category> <category><![CDATA[security vulnerability]]></category> <guid
isPermaLink="false">http://www.ghacks.net/?p=6748</guid> <description><![CDATA[Now this did not take long. Only one day after releasing a first public beta version of Google Chrome researchers at Kaspersky discovered (Thanks Neil for sending the tip) a security vulnerability that combines a security flaw in Webkit, the browser engine used by Google Chrome, with a Java bug. Apple fixed the vulnerability in [...]]]></description> <content:encoded><![CDATA[<p>Now this did not take long. Only one day after releasing a first public beta version of Google Chrome researchers at Kaspersky <a
href="http://www.readwriteweb.com/archives/security_flaw_in_google_chrome.php">discovered</a> (Thanks Neil for sending the tip) a security vulnerability that combines a security flaw in Webkit, the browser engine used by Google Chrome, with a Java bug. Apple fixed the vulnerability in Safari back in July after two months of doing nothing about it and it will be interesting to see how fast Google will react to the security vulnerability.</p><p>The reason why this vulnerability is still working in Google Chrome is because Google has been using an older version of Webkit for their browser&#8217;s core. First of all, users without Java on their computers are completely safe. Users with Java and Chrome installed should read on.</p><p>The problem is serious but requires the user&#8217;s action to be triggered. If the user clicks on a specifically prepared download the file downloads and executes itself automatically without further user input.</p><p><span
id="more-6748"></span>Security expert Aviv Raff has setup a demo website that demonstrates the vulnerability in Google Chrome. The demonstration page provides a download button which will download and execute a Java file immediately without further user interaction. This demo only opens a notepad application but serious harm could be done with such an exploit.</p> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2008/09/03/google-chrome-security-vulnerability/feed/</wfw:commentRss> <slash:comments>22</slash:comments> </item> </channel> </rss>
