• Home
  • About
  • Links
  • Contact Us

Computer Spot dot Net


Google chrome is vulnerable… watch out there’s real danger on your way!!

September 22nd, 2008 Posted by Computer Spot
in Category Featured, Internet |


Google Chrome has quickly become one of our favorite browsers occupying 1% market share on the very first day, but don’t be overwhelmed with this fact as there are many potential threats involved with the beta version currently.

Although the hot and happening web-browser from Google has barely entered the world, security researchers have been quick enough to find flaws in Chrome, which was supposed to be Google’s shiny foray into the browser market.

Before proceeding with the discussion, you can download the Google chrome beta version here & check it out yourself!

Welcome HACKERS!!

However be careful not to use it especially at cyber cafes or publicly shared systems, as you would be totally vulnerable to all the HACKERS everywhere!

Google launched the so called ideal browser; the Chrome this week, to the surprise and delight of many, but security researcher conceptually proved possibilities of exploiting the browser in a way, which takes advantage of code borrowed from an old version of Apple’s Safari.

As a result, this flaw leaves the Google browser open to carpet bombing attacks. Factually speaking, Chrome is apparently based on WebKit 525.13, which is essentially Safari 3.1, and suffers from the same flaw that Apple has since patched in its browser. That flaw, paired with a Java bug, could be used to execute code in Chrome.

A security evangelist at Kaspersky Lab, reports, Chrome has also inherited a potentially serious security flaw from the old version of WebKit it is based on.

An attacker could easily trick users into launching an executable Java file by combining a flaw in WebKit with a known Java bug and some smart social engineering, thanks to Google!

It’s actually kinda’ surprising why Google has adopted several features from other browsers like Opera, Safari and mixed them all together because maintaining all the features security-wise is very hectic and problematic.

To do so, they must track all security vulnerabilities in those features, and fix them in Chrome too. This will probably be only after those vulnerabilities were fixed by the other vendors or were publicly reported. It will put Chrome users at risk for a long time.”

Although Chrome is a handy and slick browser, but it is far from being secured as it is advertised by Google! It borrows several insecure features from other browsers, and it has its own security design flaws as well!

Let’s see the details of this security flaw, which terms Google as carpet-bombing potential victim!

Carpet-Bombing

The most threatening problem is that whenever a user double-clicks the download at the bottom of the screen, this application is opened without any warning, which allows a malicious hacker to easily execute any Java program on a user’s machine!

Many internet researchers have even set up experiments to show the vulnerability of Chrome by executing Java scripts to open a simple notepad and likes of it… So if just testers can do it easily with good-will then you can imagine what the hackers would do!!

This exploit is really embarrassing for Google as first of all, Google stressed the security of Chrome in both the official announcement as well as in the live video demo just before the launch.

Google is ignorant?

But the shocking fact is that Apple already patched WebKit against this flaw when it released Safari 3.2.1 in July, though only after the flaw had been known already for more than two months.

Google, however, is using an older version of WebKit as the basis for Chrome. Obviously, this exploit only works because of the social engineering behind it.

Just like some pop-up ads trick users into clicking “OK” because the ad mimics a typical system message in Windows, this exploit would trick users who are not yet familiar with Chrome’s interface into believing that the download is actually just part of the web page.

Hope for a better tomorrow!

Hopefully Google will patch this flaw a lot faster than Apple did, but this fact will surely put up a bit of a damper on our enthusiasm for Chrome.

Tags: apple, browser, google, Internet, safari

Related Post
Top 10 reasons to try Google Chrome
Spyware Doctor
SaveTube 3 Software
How to keep your PC healthy by avoiding viruses
How to Handle Cyber Bullying? – 5 Tips

    Leave a Reply

    ← Are You Sick of Browser Security, Filters, and Restrictions at Office? Here are Some Solutions
    Tips for buying PCI graphics cards →

    • Post Info

      • Trackback URI
      • Comments RSS
    • Website Tools

      • XSitePro Version 2
      • XSitePro Ver 2 Feature
      • Download XSitePro2 Brochure
    • Archives

      • January 2010
      • December 2009
      • November 2009
      • October 2009
      • September 2009
      • August 2009
      • July 2009
      • June 2009
      • May 2009
      • April 2009
      • March 2009
      • February 2009
      • January 2009
      • December 2008
      • November 2008
      • October 2008
      • September 2008
      • August 2008
      • July 2008
      • June 2008
      • May 2008
      • April 2008
      • March 2008
      • February 2008
      • January 2008
      • December 2007
    • Categories

      • Coffe Break (1)
      • Computer Networking (14)
      • Computer Parts (57)
        • Hard Drive (7)
        • Keyboard (2)
        • Memory (3)
        • Monitor (6)
        • Motherboard (2)
        • Mouse (6)
        • Printer (9)
        • Processor (5)
        • Sound Card (1)
        • Video Card (7)
        • WebCam (1)
      • Computer Registry (1)
      • Computer Security (43)
      • Computer Software (36)
        • Operating System (10)
      • Computer Spot (102)
      • Computer Tips (113)
      • Data Recovery (9)
      • Design (1)
      • Digital Camera (2)
      • Featured (73)
      • Games (2)
      • Internet (21)
      • Laptop / Notebook (20)
      • news (1)
      • Open Source (6)
      • Product Review (43)
      • Technology (13)
      • Web Hosting (3)
    • Blogroll

      • Computer Maintenance
      • Computer Treasure
      • Geek Adviser
      • Pc security software
    • Computer Tools

      • PC Doctor Software
      • Privacy Protector
      • Professional Uninstaller Software
    • Links

        Satellite Internet
        Now you can get broadband speed from anywhere with satellite internet from Hughes Net
    • Top Blogs
      Blog Directory & Search engine
    -->
  • Laptop computers Document Scanner


  • Computer Spot dot Net © 2007 All Rights Reserved. Powered by WordPress
    This site is hosted using Affordable and Reliable WebHosting.
    Query stats: 51 queries. 0.307 seconds.

    Entries and Comments.