In association with heise online

24 April 2009, 08:59

Google Chrome update patches XSS vulnerability

  • Twitter
  • Facebook
  • submit to slashdot
  • StumbleUpon
  • submit to reddit

Mark Larson, the Google Chrome Project Manager, has posted an advisory on the Google Chrome Releases blog advising of a high risk vulnerability in the Chrome web browser. The cross-site scripting (XSS) vulnerability is caused by an error in handling URLs in the ChromeHTML URI handler, allowing an attacker to remotely execute code, violating the same origin policy.

For an attack to be successful, a victim must first be convinced by an attacker to visit a specially crafted malicious HTML page with Internet Explorer, causing Chrome to launch, open multiple tabs and run scripts. The attack, however, only works if the Chrome browser is not already running.

Affected versions include 1.0.154.55 and earlier of the Chrome browser. Users are advised to update to version 1.0.154.59 which fixes the problem.

See also:

(crve)

Print Version | Send by email | Permalink: http://h-online.com/-741293
 


  • July's Community Calendar





The H Open

The H Security

The H Developer

The H Internet Toolkit