Google Chrome beta comes with security holes

With Google pushing a beta of their new browser Google Chrome on the front page of www.google.com, it wouldn’t be long before people started locating security problems. And first reports show that at least two problems are present, and that it isn’t ready for production systems.

Security specialist Aviv Raff has a demonstration of one problem. When you visit the page, without prompting, a file is downloaded, and the user is encouraged to click on the download. The file is actually a Java jar file which in the demonstration does nothing more than launch a Java notepad applications, but of course could carry a malicious payload.

Read more at heise open source

Comments are closed.