DCSIMG
The Browsers WAR - The art of design

The Browsers WAR

Less than a day after Google released its new sparking and shiny web browser, two major bugs where found.

image

Google’s Chrome is vulnerable to a “carpet bombing” attack. I can easily see how this may be abused by a potential attacker to make Chrome users download and execute JAR files (Java Archive) - not an applet and not inside the sandbox - without any warning. This happened because Google’s Chrome is actually based on WebKit, a former version of Safari. This vulnerability was released by Aviv Raff who wrote a harmless proof of concept.

Another less dangerous attack (for now) is that Chrome crashes. Google claims that each tab runs in its own process. This is kind of odd since when one tab crashes all other tabs crash with it. For example click here. The disturbing thing is that Chrome is exposed to a buffer overflow attack. If the example doesn’t work (security filter) just add

<a href='oded:%'>oded</a>

to your html page. It will crash.

image

One more interesting feature is popup windows that are not blocked, open in a minimized state. A potential attacker can take advantage to hide malicious consoles, because the page is rendered when it’s minimized.

Thanks,

Published Wednesday, September 03, 2008 10:18 PM by oded
תגים:

Comments

# re: The Browser WAR

Thursday, September 04, 2008 4:20 AM by Vitaly N

Put in address bar:  about:%

# Google Chrome News &raquo; Blog Archive &raquo; The Browser WAR

Wednesday, September 10, 2008 3:00 PM by Google Chrome News » Blog Archive » The Browser WAR

Pingback from  Google Chrome News  &raquo; Blog Archive   &raquo; The Browser WAR

# gBrowser

Thursday, September 11, 2008 4:42 PM by My second experiment

בעבר כבר היו שמועות על כך שגוגל מפתחת דפדפן משלה, אך בסופו של דבר לא יצא מהן כלום. כלומר, עד השבוע שעבר

Leave a Comment

(required) 
(required) 
(optional)
(required) 

Enter the numbers above:
Powered by Community Server (Commercial Edition), by Telligent Systems