Peaches Posted April 25, 2009 Report Share Posted April 25, 2009 Google Chrome update patches XSS vulnerability Mark Larson, the Google Chrome Project Manager, has posted an advisory on the Google Chrome Releases blog advising of a high risk vulnerability in the Chrome web browser. The cross-site scripting (XSS) vulnerability is caused by an error in handling URLs in the ChromeHTML URI handler, allowing an attacker to remotely execute code, violating the same origin policy.For an attack to be successful, a victim must first be convinced by an attacker to visit a specially crafted malicious HTML page with Internet Explorer, causing Chrome to launch, open multiple tabs and run scripts. The attack, however, only works if the Chrome browser is not already running.Affected versions include 1.0.154.55 and earlier of the Chrome browser. Users are advised to update to version 1.0.154.59 which fixes the problem.See also:Google Chrome "ChromeHTML" URI Vulnerability (Direct Download), security advisory from IBM Rational Application Security Group. ChromeHTML URI handler vulnerability, advisory on Google Code.Heise security: http://www.h-online.com/security/Google-Ch...y--/news/113144>>>>>>>>>>>>>> Quote Link to post Share on other sites
Recommended Posts
Join the conversation
You can post now and register later. If you have an account, sign in now to post with your account.