hat tip to shoemoney due to me playing on twitter didn’t notice in my RSS http://milw0rm.com/exploits/6355
7 Comments
-
- 2
Hi,
The “PoC Google Chrome exploit” seems to be fixed already
When I try any of the exploit test/demo I get a “Save as …” window.Nickel Chrome

- 3
Google Chrome is very fast, but with firefox i can have a lot of extensions… so… i keep my Fierfox.
- 4
This is NOT a true exploit. It only tells the browser to download a .exe file. The same “exploit” works on any other browser, the difference is that Chrome has auto-download enabled by default. So you can “Fix” this “exploit” by disabling auto-download, then Chrome will ask for a place to save the .exe file just like the other browsers.
Imo, I love the autodownload feature and it could come disabled in default configuration to the newbies

- 5
This is bad planning on chromes part, leaving auto download on by default, people exploit that.
Technically, it’s an exploit! - 6
[...] access my own bookmarks any other way except to re-enable the bar again – first exploit? (via Dave Naylor’s site) – erratic behavior especially when quickly closing a few tabs; page goes blank, even though [...]
- 7
ya it fixed already




ROTFL – is Chrome secure, isn’t it ?