Google Chrome exploit #1
- 3rd Sep 2008
- Leave a Comment
- hacking
hat tip to shoemoney due to me playing on twitter didn’t notice in my RSS http://milw0rm.com/exploits/6355
hat tip to shoemoney due to me playing on twitter didn’t notice in my RSS http://milw0rm.com/exploits/6355
6 Comments | Leave a comment »
ROTFL - is Chrome secure, isn’t it ?
Hi,
The “PoC Google Chrome exploit” seems to be fixed already :)
When I try any of the exploit test/demo I get a “Save as …” window.
Nickel Chrome :)
Google Chrome is very fast, but with firefox i can have a lot of extensions… so… i keep my Fierfox.
This is NOT a true exploit. It only tells the browser to download a .exe file. The same “exploit” works on any other browser, the difference is that Chrome has auto-download enabled by default. So you can “Fix” this “exploit” by disabling auto-download, then Chrome will ask for a place to save the .exe file just like the other browsers.
Imo, I love the autodownload feature and it could come disabled in default configuration to the newbies :)
This is bad planning on chromes part, leaving auto download on by default, people exploit that.
Technically, it’s an exploit!
[…] access my own bookmarks any other way except to re-enable the bar again - first exploit? (via Dave Naylor’s site) - erratic behavior especially when quickly closing a few tabs; page goes blank, even though […]