On Metacritic: Why Avatar will win Best Picture
BNET Business Network:
BNET
TechRepublic
ZDNet

September 5th, 2008

Google Chrome vulnerabilities starting to pile up

Posted by Ryan Naraine @ 9:33 am

Categories: Arbitrary Code Execution, Browsers, Complex Attacks, Data theft, Exploit code, Firefox, Google, Java, Malware, Pen testing, Research, Vulnerability research, Web 2.0

Tags: Google Inc., Vulnerability, Web Browser, Google Chrome, ModSecurity, Web Browsers, Security, Internet, Ryan Naraine

Google Chrome vulnerabilities starting to pile up[ UPDATE: See below for Google's official response to these issues ]

Security vulnerabilities in the new Google Chrome browser are beginning to pile up.

Following our coverage of the carpet bombing combo threat and denial-of-service crashes, several readers have sent pointers to Chrome exploit code floating around the Web:

  • First up is an automatic file download bug found by researchers in the Ukraine.  The proof-of-concept exploits (there are three) drop an executable (hack.exe) in the default download directory without any intermediate warning.
  • Vietnamese research outfit SVRT-Bkis has published demo exploits for what is described as a critical buffer overflow that could lead to remote code execution attacks.  “The vulnerability is caused due to a boundary error when handling the “SaveAs” function. On saving a malicious page with an overly long title (<title> tag in HTML), the program causes a stack-based overflow and makes it possible for attackers to execute arbitrary code on users’ systems,” the group said.  An attack scenario would require some form of social engineering.

Vulnerability researcher Robert ‘RSnake’ Hansen is very harsh in his response to Google’s decision to build its own browser:

If you build a browser in isolation, you don’t get the benefits and knowledge of the smart people who have come before you. Yes, Google’s browser is open source, like Firefox. But even Firefox came from Netscape, which had tons of background in the browser world, and Mozilla, too, has learned from a mistake or two. It is easy to call into question Google’s ability to build a safe browser given its rather poor track record in other areas of security. And no, you shouldn’t download it — not if you care about your security. So, like cryptography, you shouldn’t build a browser unless you really, really know what you’re doing.

ModSecurity’s Ivan Ristic has a different reaction to the news of Google Chrome security hiccups:

The whole point of having a public beta release is expose a product to a wide audience and deal with the discovered problems prior to a stable release. The existence of security issues in Chrome is in line with our current inability to develop software free from security issues. Thus, people should not be distracted by the small problems that are now discovered. We should be  looking at the big picture instead. Chrome is a browser that’s been designed from the ground up with security in mind. That’s bound to have a positive impact. We’ll know more about the impact once the details of its architecture surface.

Ristic however called on Google to stop abusing the “beta” tag because it unacceptably blurs the line between beta and stable. “How else are users going to be able to judge what is acceptable for production use and what isn’t?”

UPDATE:  Google’s PR team e-mailed the following statement:

  • “We became aware of this vulnerability last night and began working on a fix immediately.  We expect to release the fix soon through an automated update to the browser, so users will not have to take any action to be protected.  As always, Google asks researchers to practice responsible disclosure, so potential vulnerabilities can be evaluated and fixed before they become public and before users are subjected to unnecessary risk.  Security bugs for Google Chrome can be filed at code.google.com/p/chromium.

Ryan NaraineRyan Naraine is a journalist and security evangelist at Kaspersky Lab. He manages Threatpost.com, a security news portal. Here is Ryan's full profile and disclosure of his industry affiliations.


Email Ryan Naraine

For daily updates on Ryan's activities, follow him on Twitter.

Subscribe to Zero Day via Email alerts or RSS.

  • Talkback
  • Most Recent of 119 Talkback(s)
Absolutely ridiculous
What you just said reveals your big ignorance. The issue here is not just "bugs". The software development cycle is not primarily about bugs, but about, among other things, designing and implementing ... (Read the rest)
Posted by: markbn Posted on: 09/26/08 You are currently: a Guest | | Terms of Use
Google Chrome vulnerabilities starting to pile up  Loverock Davidson | 09/05/08
Rockhead's posts starting to pile up....  linux for me | 09/05/08
Yawn  Loverock Davidson | 09/05/08
Re: Yawn  harrisharris | 09/05/08
Yes  Loverock Davidson | 09/05/08
ROTFLMAO!!!!!  Intellihence | 09/06/08
Message has been deleted.  fairportfan | 09/08/08
Message has been deleted.  c00lways@... | 09/08/08
Go Kick Rocks, Rockhead! wink  i2fun@... | 09/08/08
Why Microsoft?  vermonter | 09/08/08
How's Your Foot Taste? wink  i2fun@... | 09/08/08
No BSOD's here  dch48 | 09/09/08
So, how goes your job search?  B.O.F.H. | 09/05/08
Message has been deleted.  Loverock Davidson | 09/05/08
Could you be any more immature?  MGP2 | 09/05/08
Wrong reply?  Loverock Davidson | 09/05/08
You're wrong again.....  MGP2 | 09/05/08
Re: You're wrong again.....  rikasa | 09/05/08
Probably not  fairportfan | 09/08/08
I can  Duke E. Love | 09/05/08
what does Ubuntu's default color scheme have to do.....  xuniL_z | 09/05/08
LOL  eMJayy | 09/06/08
posted accidentally to you. sorry. NT  xuniL_z | 09/05/08
Let's count the number of IE vulnerabilities...  jasonp@... | 09/06/08
Lets not  Loverock Davidson | 09/06/08
Yes, they did...  jasonp@... | 09/07/08
No, it's about your vitriolic post ...  914four | 09/08/08
The basis of his argument was pretty dumb to begin with...  jasonp@... | 09/08/08
ahem  shaneshack | 09/08/08
111  duhovnik | 09/09/08
Ya know...I usually would be inclined to...  techboy_z | 09/08/08
It's a BETA release  RobinInTheHood | 09/08/08
RE: Google Chrome vulnerabilities starting to pile up  squidfishes | 09/05/08
What is "beta" to Google?  flatliner | 09/05/08
Beta == Fully Operational /w Bugs  nucrash | 09/05/08
Beta is "Use with caution, you've been warned"  3dguru | 09/14/08
You misunderstand 'beta'  mdemuth | 09/05/08
Accountability-tee-hee-hee  DannyO_0x98 | 09/05/08
How's that different than ship and patch?  jasonp@... | 09/06/08
so according to you  markbn | 09/07/08
Sure, why not?  jasonp@... | 09/08/08
Absolutely ridiculous  markbn | 09/26/08
Actually  RobinInTheHood | 09/08/08
Your a funny guy...  thx-1138_@... | 09/08/08
Has nobody figured it out?  BIGELLOW | 09/05/08
RE: Google Chrome vulnerabilities starting to pile up  rikasa | 09/05/08
Two words....  MGP2 | 09/05/08
Wow... it was just released and released as beta  Been_Done_Before | 09/05/08
RE: Google Chrome vulnerabilities starting to pile up  sano1@... | 09/05/08
RE: Google Chrome vulnerabilities starting to pile up  Ashtonian | 09/05/08
Grammer important, but I am more concerned with being informed...  rcpr@... | 09/05/08
Depends on the coder.....  ncgmcpherson | 09/08/08
Grammer?  credmedia | 09/08/08
RE: Google Chrome vulnerabilities starting to pile up  dgerard | 09/05/08
I'm only glad  kcredden2 | 09/05/08
Thank you, Ryan  Userama | 09/05/08
If Chrome is this bad what's going to happen to Android? sad  T1Oracle | 09/05/08
I hate to break it to you...  BIGELLOW | 09/05/08
You can't just rewrite the definition of Beta  John Zern | 09/05/08
So please pray tell us...  jasonp@... | 09/06/08
In one word  HexHammer67 | 09/09/08
The difference is that Google....  xuniL_z | 09/05/08
Google has a worse track record...  jasonp@... | 09/06/08
when can I trust Chrome with secure browsing?  killerbunny | 09/07/08
RE: Google Chrome vulnerabilities starting to pile up  BIGELLOW | 09/05/08
NO shoddy programming???  Duke E. Love | 09/05/08
Software that isn't being debugged...  IT_User | 09/05/08
The grammatical errors are starting to pile up.  BIGELLOW | 09/05/08
Ummm  Duke E. Love | 09/05/08
Didn't MS get hammered to no end for this very thing?  xuniL_z | 09/05/08
Clueless people are led to believe in Google's great BETA products...  transposeIT | 09/06/08
One week  epcraig | 09/06/08
I like it!  bogey9000 | 09/06/08
Once again, Google is smart...  killerbunny | 09/06/08
RE: Google Chrome vulnerabilities starting to pile up  CowLauncher | 09/08/08
Chrome = Firewall Test  pyrdek | 09/08/08
What firewall do you use?  billfranke@... | 09/08/08
What Fiirewall?  pyrdek | 09/08/08
Fast, fast, fast!!!  richdave | 09/08/08
I got it! Chrome reminds me of Vista!  Breetai | 09/08/08
RE: Google Chrome vulnerabilities starting to pile up  ukmodelsuk@... | 09/08/08
RE: Google Chrome vulnerabilities starting to pile up  matty86 | 09/08/08
Safari too?  Narg | 09/08/08
The Sky IS FALLING!!!!  Narg | 09/08/08
Google Chrome  drtlhaupt | 09/08/08
Lack of information  nimrod666 | 09/08/08
Beta World 2.0  leeegeee | 09/08/08
Watch out for the Chrome TOS/EULA! Google claims to own your data!  dinosaur_z | 09/08/08
Lets hope they did a better job on that satellite (nt)  croberts | 09/08/08
There goes that security from obscurity myth  KaplanMike | 09/08/08
My beef with Google  sjbinaz | 09/08/08
GOOGLE will bury MS Explorer  bsaunders43 | 09/08/08
Idiot  SkippyH | 09/08/08
RE: Google Chrome vulnerabilities starting to pile up  david@... | 09/08/08
A very good ...  thx-1138_@... | 09/08/08
RE: Google Chrome vulnerabilities starting to pile up  lovo@... | 09/08/08
RE: Google Chrome vulnerabilities starting to pile up  dansplans@... | 09/08/08
RE: Google Chrome vulnerabilities starting to pile up  credmedia | 09/08/08
RE: Google Chrome vulnerabilities starting to pile up  duhovnik | 09/08/08
RE: Google Chrome vulnerabilities starting to pile up  duhovnik | 09/09/08
Chrome 1 week, IE 10 years  kostasan | 09/09/08
Big Question...  Too_Busy_To_Be_Here | 09/09/08
Everything hinges on the improvement trajectory  faseidl | 09/09/08
Some of the Google Security Flaws are unacceptable  jgibson24 | 09/09/08
RE: Google Chrome vulnerabilities starting to pile up  myke2@... | 09/09/08
Release an exploited code base, act surprised?  cquirke1 | 09/09/08
Debunking "endless beta" myth  bmerc | 09/09/08
Still endless beta versions though.  HexHammer67 | 09/09/08
More exploits of a vulnerability does not mean more vulnerabilities.  bmerc | 09/09/08
Works for me.  joe.smetona@... | 09/09/08
I Read the Comicbook  sjbinaz | 09/09/08
same task too large  sjbinaz | 09/09/08
A possible reason for the difficulty.  joe.smetona@... | 09/09/08
not computer, but application  sjbinaz | 09/09/08
I understand. Yes, it will take time.  joe.smetona@... | 09/10/08
RE: Google Chrome vulnerabilities starting to pile up  atari8bit@... | 09/10/08
Good point. I read that also.  joe.smetona@... | 09/11/08
DoS is a cheap shot. A crash isn't a classic DoS which was more severe  stevey_d | 09/12/08
More to the point..... wow Chrome is fast  stevey_d | 09/12/08

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement

Recent Entries

advertisement
Click Here

Archives

Favorite Links

ZDNet Blogs

White Papers, Webcasts, and Downloads

SmartPlanet

Click Here