WiredWX Christian Hobby Weather Tools
Would you like to react to this message? Create an account in a few clicks or log in to continue.

WiredWX Christian Hobby Weather ToolsLog in

 


descriptionGoogle Chrome at risk from 'carpet bomb' bug EmptyGoogle Chrome at risk from 'carpet bomb' bug

more_horiz
Blended threat can take down PCs running the browser, says researcher

(Computerworld) Attackers can combine a months-old "carpet bomb" bug with another flaw disclosed last month to trick people running Google Inc.'s brand-new Chrome browser into downloading and launching malicious code, a security researcher said today.

The attacks are possible because Google used an older version of WebKit, an open-source rendering engine that also powers Apple Inc.'s Safari, as the foundation of Chrome, said Israeli researcher Aviv Raff on Wednesday.

Raff posted a proof-of-concept exploit to demonstrate how hackers could create a new "blended threat" -- so-named because it relies on multiple vulnerabilities -- to attack Chrome, the browser Google released this week.

"This is different from the Safari/IE blended threat," said Raff in an interview conducted via instant messaging. "It's a different blend with one similar component. It uses the auto-download vulnerability (aka 'Carpet Bomb') in combination with a [user interface] design flaw and an issue with Java that doesn't display a warning on execution of JAR files downloaded from the Internet." Raff's reference to the earlier Safari/IE blended threat was to his May report that said a bug in Apple's Safari browser could be paired with an unpatched vulnerability in Microsoft Corp.'s Internet Explorer (IE) to compromise Windows PCs...............


More: http://www.computerworld.com/action/article.do?command=viewArticleBasic&articleId=9114078&source=NLT_VVR&nlid=37

............................................................................................

Please be a GeekPolice fan on Facebook!

Google Chrome at risk from 'carpet bomb' bug Lambo-11

Have we helped you? Help us! | Doctor by day, ninja by night.

descriptionGoogle Chrome at risk from 'carpet bomb' bug EmptyRe: Google Chrome at risk from 'carpet bomb' bug

more_horiz
Eeeek! I think were gonna be seeing alot of this soon unless Google can patch the hole somehow.

............................................................................................

Site Admin / Security Administrator

Virus Removal ~ OS Support ~ Have we helped you? Help us! ~ GeekChat
- Please PM me if I fail to respond within 24hrs.
Google Chrome at risk from 'carpet bomb' bug DXwU4
Google Chrome at risk from 'carpet bomb' bug VvYDg

descriptionGoogle Chrome at risk from 'carpet bomb' bug EmptyRe: Google Chrome at risk from 'carpet bomb' bug

more_horiz
I guess i wont use it first then

............................................................................................

RAW!!

descriptionGoogle Chrome at risk from 'carpet bomb' bug EmptyRe: Google Chrome at risk from 'carpet bomb' bug

more_horiz
privacy_tip Permissions in this forum:
You cannot reply to topics in this forum