On BNET: Vote: How will Apple blow it?
BNET Business Network:
BNET
TechRepublic
ZDNet

October 20th, 2008

Google readying fix for Chrome file download flaw

Posted by Ryan Naraine @ 7:16 am

Categories: Arbitrary Code Execution, Botnets, Browsers, Data theft, Exploit code, Google, Google Chrome, Java, Malware, Patch Watch, Pen testing, Vulnerability research, Web 2.0

Tags: Google Inc., Flaw, Google Chrome, Security, Ryan Naraine

Google Chrome security patchJust hours after the release of the Google Chrome browser last month, researcher Aviv Raff discovered that he could combine two vulnerabilities — a flaw in Apple Safari (WebKit) and a Java bug — to trick users into launching executables direct from the new browser. (Here’s a demo showing how a Google Chrome users can be lured into downloading and launching a JAR (Java Archive) file that gets executed without warning.

Now, it looks like Google is finally taking the threat seriously with the release of a new Chrome version to developers that  changes the download behavior for files that could execute code.

From the changelog:

  • This [version] adds prompting for dangerous types of files (executable) when they are automatically downloaded.
  • The file is saved with a temporary name (dangerous_download_xxxx.download) in the download directory and the user is presented (in the download shelf and the download tab if opened) with a warning message and buttons to save/discard the download.
  • If discarded the download is removed (and its file deleted). If saved, download goes as usual.
  • Dangerous downloads not confirmed by the user are deleted on shutdown.

ALSO SEE:
Google Chrome vulnerable to carpet-bombing flaw

Google Chrome, the security tidbits

Ryan NaraineRyan Naraine is a journalist and security evangelist at Kaspersky Lab. He manages Threatpost.com, a security news portal. Here is Ryan's full profile and disclosure of his industry affiliations.


Email Ryan Naraine

For daily updates on Ryan's activities, follow him on Twitter.

Subscribe to Zero Day via Email alerts or RSS.

  • Talkback
  • Most Recent of 11 Talkback(s)
RE: Why use Apple Crap
Webkit existed before Safari. The fact that Apple uses
it has nothing to do with this problem.

And frankly, it's not crap... they have the earnings
to prove it... and no I don't own a Macintosh.

-M... (Read the rest)
Posted by: betelgeuse68 Posted on: 10/23/08 You are currently: a Guest | | Terms of Use
Good  MrViklund | 10/20/08
hmm  Narr vi | 10/20/08
What ... there is another flaw in Chrome?  rmark@... | 10/20/08
Whats your point?  thelivo | 10/20/08
Who decides what is dangerous?  forrestgump2000@... | 10/20/08
16805 employees no beta-testers  topsecret@... | 10/20/08
not spending it on beta testing  tikigawd | 10/21/08
RE: Google readying fix for Chrome file download flaw  rickmlenator@... | 10/21/08
Symantec Endpoint Protection  adzmsane | 10/21/08
Why use Apple Crap  graham.lv | 10/21/08
RE: Why use Apple Crap  betelgeuse68 | 10/23/08

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement

Recent Entries

advertisement

Archives

Favorite Links

ZDNet Blogs

White Papers, Webcasts, and Downloads

SmartPlanet

Click Here