Apr 24, 2009

Google Chrome 1.0.154.59 Released

Google Chrome's Stable channel has been updated to 1.0.154.59 to fix a security issue:

CVE-2009-1340 ChromeHTML protocol handler same-origin bypass
An error in handling URLs with a chromehtml: protocol could allow an attacker to run scripts of his choosing on any page or enumerate files on the local disk under certain conditions.

If a user has Google Chrome installed, visiting an attacker-controlled web page in Internet Explorer could have caused Google Chrome to launch, open multiple tabs, and load scripts that run after navigating to a URL of the attacker's choice. Such an attack only works if Chrome is not already running.

See http://code.google.com/p/chromium/issues/detail?id=9860 for more details.

Affected versions: 1.0.154.55 and earlier

Severity: High. This allows universal cross-site scripting (UXSS) without user interaction under certain conditions.

Credit: Roi Saltzman (roisa@il.ibm.com) Security Researcher at IBM Rational Application Security Research Group

-- Mark Larson
Google Chrome Program Manager

Download: Google Chrome 1.0.154.59

No comments:

Boorkmark & Share

Bookmark Options