Tuesday, December 02, 2008

Google Chrome Beta Security Update

Google Chrome Beta 0.4.154.29 update addresses the following security issue:
"Gears Cross-Origin Worker Vulnerability
CVE: CVE-2008-5258
A vulnerability in Gears could allow an attacker to run code in the context of a site that serves user-controlled files. To exploit this, an attacker needs to upload a malicious file to the victim's site and convince the user to allow the attacker's site to use Gears.

Severity: High. Even though this requires convincing users to allow a third-party site to use Gears, it could allow data theft and cross-site scripting on sites hosting user-created content, even those that do not use Gears.
Credit: Thanks to Yair Amit, Senior Security Researcher, IBM Rational Application Security Research Team for responsibly reporting the issue to Google."
Reminder: It is not advisable to use Beta software on production systems.

Reference:





Remember - "A day without laughter is a day wasted."
May the wind sing to you and the sun rise in your heart...

No comments: