Google Plugs 'High Risk' Flaws in Chrome

Talk about and discuss various advancements and achievents in the arts and sciences of invention and modification; computers, sciences, mathematics, and technology for all.
Post Reply
User avatar
AYHJA
392
Posts: 37990
Joined: Fri Sep 17, 2004 2:25 pm
Location: Washington, D.C.
Contact:

Google Plugs 'High Risk' Flaws in Chrome

#1

Post by AYHJA »

Image

Google has shipped another Chrome browser update to fix multiple security security vulnerabilities.

Some of these security holes can be exploited by malicious people to conduct spoofing attacks, bypass certain security restrictions, and potentially compromise a user’s system, according to this Secunia advisory.Secunia rates this a “highly critical” update.

According to this basic documentation, there are a total of 11 vulnerabilities in this patch batch. Google is withholding details on most of the serious vulnerabilities until the majority of Chrome users are fully patches.

Some of the flaws affect Linux users only.

* [48225] [51727] (Medium-risk) Possible autofill / autocomplete profile spamming.
* [48857] (High-risk) Crash with forms.
* [50428] (Critical) Browser crash with form autofill. Credit to the Chromium development community.
* [51680] (High-risk) Possible URL spoofing on page unload.
* [53002] (Low-risk) Pop-up block bypass.
* [53985] (Medium-risk) Crash on shutdown with Web Sockets.
[Linux only] [54132] (Low-risk) Bad construction of PATH variable.
* [54500] (High-risk) Possible memory corruption with animated GIF. Credit to Simon Schaak.
* [Linux only] [54794] (High-risk) Failure to sandbox worker processes on Linux.
* [56451] (High-risk) Stale elements in an element map.

Google paid $1,000 in bounties to researchers who reported two of the 11 vulnerabilities.

More/Source: http://sn.im/1bnzwb

BBcode:
Hide post links
Show post links
User avatar
jdog
Posts: 3318
Joined: Tue Feb 15, 2005 5:59 pm

Re: Google Plugs 'High Risk' Flaws in Chrome

#2

Post by jdog »

If you are using Linux then you shouldn't even bother with Chrome. Stick with Chromium instead.
If any links are down, please send me a PM!

BBcode:
Hide post links
Show post links
User avatar
AYHJA
392
Posts: 37990
Joined: Fri Sep 17, 2004 2:25 pm
Location: Washington, D.C.
Contact:

Re: Google Plugs 'High Risk' Flaws in Chrome

#3

Post by AYHJA »

I don't get it...Are you saying Windows users get Chrome, Linux gets Chromium..? What's the difference..?

BBcode:
Hide post links
Show post links
User avatar
jdog
Posts: 3318
Joined: Tue Feb 15, 2005 5:59 pm

Re: Google Plugs 'High Risk' Flaws in Chrome

#4

Post by jdog »

Chromium is the open source version. It's primarily for Linux users but there is one made for Windows.
If any links are down, please send me a PM!

BBcode:
Hide post links
Show post links
Post Reply