View Full Version : Google Chrome binary planting vulnerability
MrBrian
October 23rd, 2011, 09:14 AM
From http://secunia.com/advisories/46471/:
-{ Quote: "A vulnerability has been reported in Google Chrome, which can be exploited by malicious people to compromise a user's system.
The vulnerability is caused due to the application bundling a vulnerable version of the NSS library." }-
funkydude
October 23rd, 2011, 09:22 AM
I like the solution!
-{ Quote: "Solution
Do not open files from untrusted sources." }-
m00nbl00d
October 23rd, 2011, 10:19 AM
Well, considering that most Google Chrome users are probably using Google has their search engine, and it now opens in https, then they are not at danger.
Any other https works fine, as well.
-{ Quote: "
Because of the "first HTTPS connection" requirement, this attack can't
work if user's default search engine is Google, as this triggers an
HTTPS connection upon Chrome startup. (Which results in an attempt to
load pkcs11.txt from "C:\".)
" }-
Source: -https://code.google.com/p/chromium/issues/detail?id=97426
vBulletin® Copyright ©2000-2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums