You are here: silicon.com > Software > Security Strategy

Security Strategy

Google plugs severe security hole in Chrome

Fixing the scripts

Tags: security, chrome, google

By Stephen Shankland

Published: 24 April 2009 09:07 GMT

Google released a new version of its Chrome browser Thursday to fix a high-severity security problem.

The problem affects Google's mainstream stable version of Chrome and is fixed in the new version 1.0.154.59. Google has built Chrome so it updates itself automatically with no user intervention, though the software must be restarted for the new version to run.

The security problem, reported 8 April by Roi Saltzman of the IBM Rational Application Security Research Group, allowed cross-site scripting attacks. Such methods can make a web browser process unauthorised code such as JavaScript, enabling a variety of attacks, including impersonation or phishing.

Mark Larson, Google Chrome programme manager, described the problem in a blog posting Thursday as "an error in handling URLs with a chromehtml: protocol could allow an attacker to run scripts of his choosing on any page or enumerate files on the local disk under certain conditions".

"If a user has Google Chrome installed, visiting an attacker-controlled web page in Internet Explorer could have caused Google Chrome to launch, open multiple tabs, and load scripts that run after navigating to a URL of the attacker's choice. Such an attack only works if Chrome is not already running," the blog said.

Original article: Google fixes severe Chrome security hole from CNET News.com

  1. Zones
  2. Management
  3. Networks
  4. Software
  5. IT Services
  6. Hardware
  1. Verticals
  2. Public Sector
  3. Financial Services
  4. Retail & Leisure

Clive Longbottom Windows 7: Not perfect - but ready for prime time Microsoft's latest OS fixes most of Vista's ills - but still has challenges ahead

Stephen Kleynhans Mind the details with Windows 7 Just because it might work better than Vista, it doesn't mean you can be sloppy


  • Jobs
PHP Developer, Online Design Agency, Basingstoke - 35k - 40k

Knowledge of browser quirks and variations SEO and SEM understanding and ability to use Google Analytics PHP Developer, Online Design Agency, ...

Website Tester - Staffordshire, West Midlands - Payment Testing, Cross-Browser Testing, Testing Tools,

Website Tester - Staffordshire, West Midlands - Payment Testing, Cross-Browser Testing, Testing Tools, My Staffordshire based client requires a ...

Web Developer / PHP Developer- Joomla or Magento CMS - Google Accredited Agency

This means that you would be joining a company with a reputation for delivering the best work and results to some of the county's leading brands.We ...

Agenda Setters 2009
Welcome to the ninth annual Agenda Setters poll – silicon.com's list of the top 50 most influential individuals in the technology and IT industries, from techies and CIOs to entrepreneurs and business leaders. Find out more in our latest special report.





Quick Sitemap Links: