On UrbanBaby: Nanny vs. Daycare. Discuss!
BNET Business Network:
BNET
TechRepublic
ZDNet

June 11th, 2009

Google plugs 'high risk' WebKit holes in Chrome

Posted by Ryan Naraine @ 7:50 am

Categories: Anti Virus, Arbitrary Code Execution, Browsers, Complex Attacks, Data theft, Exploit code, Google, Google Chrome, Hackers, Malware, Open source, Patch Watch, Pen testing

Tags: Google Inc., Attacker, Web Browser, Google Chrome, Sandbox, Web Browsers, Security, Internet, Ryan Naraine

Google has shipped a Chrome browser update to fix two serious security issues in WebKit.

According to Google Chrome program manager Mark Larson, the most serious of the two flaws could allow hackers to execute harmful code in the browser’s sandbox.  It is rated “high severity.”

From Google’s advisory:

A memory corruption issue exists in WebKit’s handling of recursion in certain DOM event handlers. Visiting a maliciously crafted website may lead to a tab crash or arbitrary code execution in the Google Chrome sandbox. This update addresses the issue through improved memory management.

[ SEE: Study: Silent patching best for securing browsers ]

For an attack to be successful, the victim would havve to visit a Web page under the attacker’s control.  Larson said that any code that an attacker might be able to run inside the renderer process would be inside the sandbox.

The update also fixes:

An issue exists in WebKit’s handling of drag events. This may lead to the disclosure of sensitive information when content is dragged over a maliciously crafted web page. This update addresses the issue through improved handling of drag events.

Google rates this a “medium” severity bug and warns that an attacker might be able to read data belonging to another web site, if a user can be convinced to select and drag data on an attacker-controlled site.

The patch is being pushed out to Google Chrome via the browser’s silent/automatic update mechanism.

Ryan NaraineRyan Naraine is a journalist and security evangelist at Kaspersky Lab. He manages Threatpost.com, a security news portal. Here is Ryan's full profile and disclosure of his industry affiliations.


Email Ryan Naraine

For daily updates on Ryan's activities, follow him on Twitter.

Subscribe to Zero Day via Email alerts or RSS.

  • Talkback
  • Most Recent of 4 Talkback(s)
Browser reaches out
It is the browser that reaches out to Google servers and polls for updates. To intercept that traffic an attacker needs control of your network and/or DNS servers.

Even so, Chrome presumably co... (Read the rest)
Posted by: honeymonster Posted on: 06/14/09 You are currently: a Guest | | Terms of Use
Silent updating a risk in itself?  jjourard | 06/11/09
Right  megamanx | 06/12/09
Browser reaches out  honeymonster | 06/14/09
Microsoft Problem  dougbeer | 06/11/09

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement

Recent Entries

advertisement

Archives

Favorite Links

ZDNet Blogs

White Papers, Webcasts, and Downloads