Vulnerabilities/Bugs in Chrome – Issues till Now !!

image Chrome beta has received mixed responses from the blogging world but now it is time for outlining some vulnerabilities and issues with Chrome ( that’s why a beta is launched :) ) Here are some I found out through various Security websites ..

1. Open Chrome and type ":%" without quotes and it crashes , it happens for any  URL too, so even if you type "Google.com:%" it will crash …

2. Another vulnerability found at milw0rm.com that makes Chrome crash is

Click Here (from inside chrome)  and it will crash your Chrome browser !!

( basically it injects a very long .psd filename in your header and chrome cant handle it )

3. Chrome does not asks before downloading .exe files , and this is not considered good from security point of view !!

4. Open to "Carpet Bombing" , ie. if a web page contains link to filetypes with absurd extensions(content-type:"blah/blah") then a web page can fill up your Desktop or download directory with thousand of files … [more details by Nitesh Dhanjani] this was first found in Safari ( Apple’s Web Browser ) but chrome is also affected with it .

Carpet Bombing in Safari ( see the Desktop and Download window ) image

Hope the Google Team looks into these issues and get’s them solved out in upcoming release , after all this was just a beta release of Chrome ..


This entry was posted on Friday, September 5th, 2008 and is filed under Google, Security. You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback from your own site.

Leave a Reply

See What others were Looking For !!

chrome (1)