Gå till innehåll

Recommended Posts

Postad

3 September 2008, 14:43

Google Chrome beta comes with security holes

 

http://www.heise-online.co.uk/security/Google-Chrome-beta-comes-with-security-holes--/news/111458

The vulnerability appears to use a vulnerability in Webkit, previously noted in Safari, called Carpet Bomb and a bug in Java. With the Safari Carpet Bomb, Safari downloaded DLL files to the desktop automatically, which were, for reasons unknown, automatically executed by Windows at startup. Apple has defused the Carpet Bomb in Safari 3.1.2, but Chrome uses an earlier branch of the Webkit renderer and still has the problem.

 

Another problem was found in Chrome's protocol handling, as a demonstration page shows. The protocol handler name has a "special" character at the end of its name, and this character causes the handler to crash, taking down the browser. The failure appears to be down to the protocol handler not being isolated to a process in Chrome's multi-process architecture.

 

See Also:

edit:

även i Sitics senaste veckobrev finns en hel del länkar om chrome:

http://www.sitic.se/publikationer/veckobrev/sitics-veckobrev-v-36-1

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Gäst
Svara i detta ämne...

×   Du har klistrat in innehåll med formatering.   Ta bort formatering

  Endast 75 max uttryckssymboler är tillåtna.

×   Din länk har automatiskt bäddats in.   Visa som länk istället

×   Ditt tidigare innehåll har återställts.   Rensa redigerare

×   You cannot paste images directly. Upload or insert images from URL.

×
×
  • Skapa nytt...