Google Chrome's Stable channel has been updated to 1.0.154.59 to fix a security issue:
CVE-2009-1340 ChromeHTML protocol handler same-origin bypass
An error in handling URLs with a chromehtml: protocol could allow an attacker to run scripts of his choosing on any page or enumerate files on the local disk under certain conditions.
If a user has Google Chrome installed, visiting an attacker-controlled web page in Internet Explorer could have caused Google Chrome to launch, open multiple tabs, and load scripts that run after navigating to a URL of the attacker's choice. Such an attack only works if Chrome is not already running.
See http://code.google.com/p/chromium/issues/detail?id=9860 for more details.
Affected versions: 1.0.154.55 and earlier
Severity: High. This allows universal cross-site scripting (UXSS) without user interaction under certain conditions.
Credit: Roi Saltzman (roisa@il.ibm.com) Security Researcher at IBM Rational Application Security Research Group
-- Mark Larson
Google Chrome Program Manager
Download: Google Chrome 1.0.154.59
No comments:
Post a Comment