On mySimon: Kidkraft Savannah Dollhouse
BNET Business Network:
BNET
TechRepublic
ZDNet

September 3rd, 2008

DoS vulnerability hits Google's Chrome, crashes with all tabs

Posted by Dancho Danchev @ 7:19 am

Categories: Black Hat, Browsers, Denial of Service (DoS), Google, Hackers, Pen testing, Research, Responsible disclosure, Vulnerability research, Zero-day attacks

Tags: Google Chrome, Rishi Narang, Proof of Concept, Dancho Danchev

In Focus » See more posts on: Google Chrome

Chrome crashingWhoa! Google Chrome has crashed. Restart now? While Google’s Chrome team is cheering, Rishi Narang from Evil Fingers is typing and releasing a proof of concept for a denial of service vulnerability that is successfully crashing the Chrome browser with all tabs. According to Narang’s advisory :

“An issue exists in how chrome behaves with undefined-handlers in chrome.dll version 0.2.149.27. A crash can result without user interaction. When a user is made to visit a malicious link, which has an undefined handler followed by a ’special’ character, the chrome crashes with a Google Chrome message window “Whoa! Google Chrome has crashed. Restart now?”. It crashes on “int 3″ at 0×01002FF3 as an exception/trap, followed by “POP EBP” instruction when pointed out by the EIP register at 0×01002FF4.”

Nothing’s impossible the impossible just takes a little longer.

Also see: Google Chrome vulnerable to carpet-bombing flaw

Whenever a new product is in its introduction stage, it would logically attract a lot of attention from security researchers trying to a make a point that it’s vulnerable, and that some of the vulnerabilities are pretty trivial. For instance, yesterday David Maynor from Errata Security pin pointed possibilities for exploitation in Google’s Chrome, saying that :

“Google just released Chrome, their own web browser. We decided to run it through Looking Glass and it doesn’t look half bad. They at least have ASLR enabled on a few of their libraries, no NX though. Chrome is not as bad as some apps I have seen but that is not saying much.”

What’s important though, is whether or not the browser release would also start attracting the attention of cybercriminals.Chrome Errata Security Being anything but old-fashioned, they too do their homework and take into consideration the market share of a particular browser in order to increase the impact of exploiting it. Consequently, for the time being the level of exploitability of Google’s Chrome is right after Opera’s from the perspective of the malicious attacker taking into consideration Chrome’s non-existent market share.

Would the level of exploitability change? In the fist quarter of 2009, Google would presumably release stats of the number of people who downloaded Chrome, demonstrating nothing else but the introduction stage of their browser. The question is, how many of those who downloaded it would actually stick with it, and would companies embrace it if it does gets popular enough, potentially increasing the exploitability level of any upcoming vulnerabilities?

Considering the fact that according to public statistics of usage share of web browsers, IE6 users are just as many as IE7 ones, converting from Firefox or IE to Google’s Chrome is not going to happen overnight.

Dancho DanchevDancho Danchev is an independent security consultant and cyber threats analyst, with extensive experience in open source intelligence gathering, malware and cybercrime incident response. He's been an active security blogger since 2007, and maintains a popular security blog. See his full profile and disclosure of his industry affiliations.

Email Dancho Danchev

Subscribe to Zero Day via Email alerts or RSS.

  • Talkback
  • Most Recent of 118 Talkback(s)
Windows
I consider myself an average user over 35. I used Windows 2000 for awhile when I was given an older P3 computer. I use Firefox, don't much like IE at all. Now I have a newer computer, I'm thinking of ... (Read the rest)
Posted by: perversion2003@... Posted on: 01/12/09 You are currently: a Guest | | Terms of Use
Chrome will have security problems, and they will NOT all of a sudden gain  DonnieBoy | 09/03/08
Anyone on Windows 2000 Now -- Will Not Consider Anything But Windows  PMC-CON | 09/03/08
How about those of us over 2 * 35 . . ..?  NeverLift | 09/03/08
I am also over 70 and...  mietz | 09/04/08
aaaah the old times  missplaced | 09/05/08
Bust out that abacus!  tikigawd | 09/04/08
whoa!  dgrainge | 09/04/08
Cheap #1 & Lazy #2  wellduh | 09/07/08
Windows  perversion2003@... | 01/12/09
Seriously  waterhzrd | 09/03/08
Doubt Google will gain much of anything  snaresV64 | 09/03/08
Nice way to explain away vulnerabilities...It's BETA  transposeIT | 09/03/08
Amen!  armith@... | 09/04/08
Is it more honest to call it a Beta perpetually...  technology@... | 09/04/08
Beta Perpetually?  ManoaHI | 09/04/08
Everything is beta really...  Duke E. Love | 09/05/08
Boy  dontnetcoder | 09/04/08
Wrong wrong wrong wrong wrong, as wrong as you can be.  Cayble | 09/04/08
I disagree.  joe.smetona@... | 09/05/08
RE: DoS vulnerability hits Google's Chrome, crashes with all tabs  Loverock Davidson | 09/03/08
More time testing before deployment  sundby@... | 09/03/08
Beta software IS for testing  davidr69 | 09/03/08
This ones an Alpha  tech_walker | 09/03/08
Not surprising...  Wolfie2K3 | 09/04/08
I fail to understand-  madmanjohn | 09/06/08
Good post  Tynach | 09/03/08
Sure, right...if and only if...  Cayble | 09/04/08
for testing, huh?  craiglarry | 09/03/08
Says one fanboi to another...  jasonp@... | 09/04/08
Keep in mind...  Cayble | 09/04/08
almost like Microsoft  mluther223@... | 09/04/08
Get real  Cayble | 09/04/08
Ehmmm  TedKraan | 09/04/08
Chrome download seems disabled for now...  dpnewkirk | 09/03/08
Chrome DL is still working  scudrunner | 09/03/08
They don't have to take it down.  joe.smetona@... | 09/03/08
unattended updates. Really?  dgrainge | 09/04/08
Here's some more information.  joe.smetona@... | 09/04/08
RE: DoS vulnerability hits Google's Chrome, crashes with all tabs  matojo2006 | 09/03/08
Much ado...  betelgeuse68 | 09/03/08
or better yet  rtk | 09/03/08
RemoveAdmin  Jack Fuller | 09/05/08
Version 0.2.149.27?  JonathonDoe | 09/03/08
Just a thought..  joe.smetona@... | 09/03/08
RE: DoS vulnerability hits Google's Chrome, crashes with all tabs  websan | 09/03/08
The browser crashes with a certain link - that isn't a DoS  stevey_d | 09/03/08
The term has been hijacked  NonZealot | 09/03/08
that's crazy  stevey_d | 09/12/08
Good point.  joe.smetona@... | 09/15/08
DoS can also mean  jhimes | 09/03/08
Ads?  pahosler@... | 09/04/08
I guess DDOS  alaniane@... | 09/03/08
OMG - beta software with bugs!!!  davidr69 | 09/03/08
What Version of Beta is GMail?  PMC-CON | 09/03/08
Ethereal/Wireshark  davidr69 | 09/03/08
Google and the perpetual Beta state of it's offerings is a nice excuse when  transposeIT | 09/03/08
They do release full products, however  Li1t | 09/04/08
RE: DoS vulnerability hits Google's Chrome, crashes with all tabs  hearse trax | 09/03/08
RE: DoS vulnerability hits Google's Chrome, crashes with all tabs  hearse trax | 09/03/08
RE: DoS vulnerability hits Google's Chrome, crashes with all tabs  link2dan | 09/03/08
Welcome to the big leagues  John L. Ries | 09/03/08
RE: DoS vulnerability hits Google's Chrome, crashes with all tabs  rbeberaggi@... | 09/03/08
RE: DoS vulnerability hits Google's Chrome, crashes with all tabs  TSGlassey | 09/03/08
RE: DoS vulnerability hits Google's Chrome, crashes with all tabs  cardinal33 | 09/03/08
Windows vista 64-bit  rebelxhardcore | 09/03/08
Give it a try  vmaatta | 09/04/08
RE: DoS vulnerability hits Google's Chrome, crashes with all tabs  rwmiller@... | 09/03/08
RE: DoS vulnerability hits Google's Chrome, crashes with all tabs  taylor@... | 09/03/08
RE: DoS vulnerability hits Google's Chrome, crashes with all tabs  mballai | 09/03/08
there's public and private  dgrainge | 09/04/08
What can we expect?  bitshiftr | 09/03/08
it's not that you just don't like Firefox.  deowll | 09/04/08
RE: What we can expect...  gypkap@... | 09/03/08
Its not that great  custserv@... | 09/03/08
man theres something very wrong  clava | 09/03/08
RE: DoS vulnerability hits Google's Chrome, crashes with all tabs  akbose_2007@... | 09/03/08
RE: DoS vulnerability hits Google's Chrome, crashes with all tabs  atari8bit@... | 09/03/08
RE: DoS vulnerability hits Google's Chrome, crashes with all tabs  hoppity | 09/03/08
RE: DoS vulnerability hits Google's Chrome, crashes with all tabs  MarkHarrison | 09/04/08
Why GOOG fool users :  sandalin | 09/04/08
Missing The Significance  jdieter@... | 09/04/08
RE: DoS vulnerability hits Google's Chrome, crashes with all tabs  martinfrey@... | 09/04/08
Video Walkthrough - Chrome Browser  pcwizkid.tech.talk@... | 09/04/08
RE: Chrome -- Underwhelming.  Mr_Wizard | 09/04/08
Just another browser  jscott418 | 09/04/08
Why the Complaining already  ryanlee05 | 09/04/08
RE: DoS vulnerability hits Google's Chrome, crashes with all tabs  public@... | 09/04/08
Chrome is not "polished" enough  dr.lal.dallas@... | 09/04/08
It STILL mops the floor with IE, Firef__ks, Sufferi, and Oprah  XweAponX | 09/04/08
Acronyms  snakecharmernyc@... | 09/04/08
RE: DoS vulnerability hits Google's Chrome, crashes with all tabs  scofrezo | 09/04/08
Ryan Naraine, Dancho Danchev  i2fun@... | 09/04/08
Chrome is not fit to be called a beta  dieter.donnert@... | 09/04/08
RE: DoS vulnerability hits Google's Chrome, crashes with all tabs  deowll | 09/04/08
Timing is all.  ozzie_tech | 09/04/08
MS Advertising 300M$ - Google, priceless  joe.smetona@... | 09/05/08
Not everyone sees the 'ad'  sbrown@... | 09/05/08
Good Point. I have iGoogle set up also.  joe.smetona@... | 09/05/08
RE: DoS vulnerability hits Google's Chrome, crashes with all tabs  wanderson | 09/05/08
It happens all the time here.  joe.smetona@... | 09/05/08
please point out the article  rtk | 09/05/08
Article link.  joe.smetona@... | 09/05/08
what article  rtk | 09/05/08
Did you read the article?  joe.smetona@... | 09/06/08
Despite your best efforts  rtk | 09/06/08
RE: DoS vulnerability hits Google's Chrome, crashes with all tabs  dgerard | 09/05/08
Chrome is great-Security? Bah humbug!  madmanjohn | 09/06/08
RE: Despite your best efforts (RTK)  joe.smetona@... | 09/06/08
Some suggestions.  joe.smetona@... | 09/06/08
great general safe computing practices.  rtk | 09/06/08
You making this up as you go along?  rtk | 09/06/08
If you pull the plug on the computer...  joe.smetona@... | 09/06/08
What?!?!?!?  rtk | 09/06/08
Not without a test case and t causes damage.proof that i  joe.smetona@... | 09/06/08
It's pretty clear  rtk | 09/06/08
Link.  joe.smetona@... | 09/08/08
If Chrome goes GPL it will grab shares fast  wellduh | 09/07/08
RE: DoS vulnerability hits Google's Chrome, crashes with all tabs  damacman | 09/07/08

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement

Recent Entries

advertisement

Archives

Favorite Links

ZDNet Blogs

White Papers, Webcasts, and Downloads

SmartPlanet

Click Here