Google patches severe Chrome vulnerabilities
Google has fixed two high-severity vulnerabilities in the stable version of its Chrome browser that could have let an attacker remotely take over a person's computer.
With one attack on Google's V8 JavaScript engine, malicious JavaScript on a Web site could let an attacker gain access to sensitive data or run arbitrary code on the computer within a Chrome protected area called the sandbox, Google said in a blog post Tuesday. With the other, a page with XML-encoded information could cause a browser tab crash that could let an attacker run arbitrary code within the sandbox.
Chrome 2.0.172.43 (click to download for Windows) fixes the issues and another medium-severity issue. Once Chrome is installed, it retrieves updates automatically and applies them when people restart the browser.
Google won't release details of the vulnerabilities until "a majority of users are up to date with the fix," Engineering Program Manager Jonathan Conradt said in the blog post.
Stephen Shankland writes about a wide range of technology and products, but has a particular focus on browsers and digital photography. He joined CNET News in 1998 and since then also has covered Google, Yahoo, servers, supercomputing, Linux and open-source software, and science. E-mail Stephen, or follow him on Twitter at http://www.twitter.com/stshank. 





- by aitchondo August 27, 2009 11:51 PM PDT
- Who is the "poor fool" who thinks a Mac doesn't get infected? I'm using my PC right now, Windows Browser, but will be on the Unix shortly, with Firefox. Firefox, believe it or don't, isn't that secure on a regular PC. As for Chrome, some people may like it, like they like the new line of cars out there, but some of us need more... Shelby Cobra rules!
- Like this Reply to this comment
-
(40 Comments)