• On The Insider: Britney's Bikini-Clad Top 10
May 7, 2009 5:43 PM PDT

Google issues, then reissues Chrome security fix

by Stephen Shankland
  • Font size
  • Print
  • 10 comments

Google fixed security holes with a new release of its stable version of Chrome--then released a replacement shortly afterward to prevent a batch of crashes that turned up as well.

Chrome 1.0.154.64 (download) emerged Tuesday and was intended to fix one critical security problem and one high-severity one. On Thursday, came 1.0.154.65 to fix a crash during startup that affected "a small percentage of users," said Chrome Program Manager Mark Larson.

With the first problem, an attacker under some circumstances could run attack software with the same privilege as the computer user.

With the second, an issue handling 2D graphics could potentially allow a specially crafted image to crash a tab and run an attacker's code within Chrome's sandbox security isolation system.

Originally posted at Webware
Stephen Shankland writes about a wide range of technology and products, but has a particular focus on browsers and digital photography. He joined CNET News in 1998 and since then also has covered Google, Yahoo, servers, supercomputing, Linux and open-source software, and science. E-mail Stephen, or follow him on Twitter at http://www.twitter.com/stshank.
advertisement
Click Here
Recent posts from Security
Pub fined $13k for Wi-Fi copyright infringement
Tips for safe online shopping
Big changes in Security Starter Kit 2010
Confidential 9/11 pager messages disclosed
Microsoft warns of IE exploit code in the wild
Chrome OS security: 'Sandboxing' and auto updates
E-tailers snagged in marketing 'scam' blame customers
McAfee warns about '12 Scams of Christmas'
Add a Comment (Log in or register) (10 Comments)
  • prev
  • 1
  • next
by derilium May 7, 2009 7:05 PM PDT
If it runs within the sandboxed security, how is it a threat?
Reply to this comment
by Shankland May 7, 2009 7:26 PM PDT
You don't want arbitrary malicious code running anywhere. Better in a sandbox than out of it, but better not at all. I'm not sure it applies to browser sandboxes, but with operating system attacks, an attempt can combine two subattacks--one to run arbitrary code in a limited fashion and another to escalate privileges.
by May 7, 2009 9:08 PM PDT
Hahaha.. I bet if this was IE7/8 all the apple-fanboys and *nix thugs would be talking smack in here like crazy...
Reply to this comment
by sd_response May 8, 2009 8:44 AM PDT
hahah..couldn't agree more. I guess they have double standards after all...I have both IE 8 and latest FireFox in my system. But I mostly use IE on my machine. Never installed Chrome never will...
by Kasee May 7, 2009 9:42 PM PDT
I discontinued Google Chrome - just because of missing features like - Google Bookmarks synchronization, addon support to Xmarks, many of my SAP portals dont work properly in Google chrome; Google chrome is not synching google search to my webhistory? I get everything from Firefox and latest beta performance is too good compared to previous ones;
Reply to this comment
by profdavidson May 9, 2009 2:38 PM PDT
Kasee apparently is still learning basic English but still has enough time to worry about her internet browser
Reply to this comment
by kill pcs May 10, 2009 2:16 AM PDT
All new programs take some time to get right. Chrome may seem a bit basic but that is what some people want.Give it as long as firefox &ie then see if it is as bad as you think.
Reply to this comment
by i_made_this May 14, 2009 9:30 AM PDT
There's some irony in Google's having taken Chrome out of Beta, only to release three immediate highly critical security patches in RTM. We tried Chrome and liked it very much. We didn't like its installation of all sorts of other Google background programs including a pair of all-encompassing *Google Miscellaneous* type programs which forced themselves to run as start-up and when disabled, they reproduced themselves lol. Google, dudes, we're aware you guys are seriously brilliant hackers and that you adore Windows for this reason, but c'mon... . PS Ya, all of what I've said is buried in the most massive EULA any browser has ever required that you sign.
Reply to this comment
by Bozz5384 May 18, 2009 5:32 AM PDT
Google Chrome is still the best browser I have found, period. It runs circles around IE and FireFox, and uses about 1/2 the resources of IE, and about 1/3 of FireFox loading and displaying the same websites... its not perfect, but its soooo much better than anything else out there.
Reply to this comment
by fdunn3 May 20, 2009 6:22 AM PDT
Also the best means of someone injecting code into your system.....REAL FAST though!
(10 Comments)
  • prev
  • 1
  • next
advertisement

The browser battles go on and on

roundup From Firefox to IE and from Chrome to Opera and Safari, there's no sitting still for browser makers looking to keep their products fresh and competitive.

3G wireless still holds promise

The next generation of 4G wireless may get all the headlines, but advanced 3G technology will likely dominate services for the next few years.

About Security

Online security is threatened by more than hacking and phishing attempts. Check here for the latest updates on software vulnerabilities, data leaks, and rapidly spreading viruses--and learn how to protect your systems.

Add this feed to your online news reader

Security topics

advertisement
advertisement

Inside CNET News

Scroll Left Scroll Right