Chrome beta has received mixed responses from the blogging world but now it is time for outlining some vulnerabilities and issues with Chrome ( that’s why a beta is launched
) Here are some I found out through various Security websites ..
1. Open Chrome and type ":%" without quotes and it crashes , it happens for any URL too, so even if you type "Google.com:%" it will crash …
2. Another vulnerability found at milw0rm.com that makes Chrome crash is
Click Here (from inside chrome) and it will crash your Chrome browser !!
( basically it injects a very long .psd filename in your header and chrome cant handle it )
3. Chrome does not asks before downloading .exe files , and this is not considered good from security point of view !!
4. Open to "Carpet Bombing" , ie. if a web page contains link to filetypes with absurd extensions(content-type:"blah/blah") then a web page can fill up your Desktop or download directory with thousand of files … [more details by Nitesh Dhanjani] this was first found in Safari ( Apple’s Web Browser ) but chrome is also affected with it .
Carpet Bombing in Safari ( see the Desktop and Download window )
Hope the Google Team looks into these issues and get’s them solved out in upcoming release , after all this was just a beta release of Chrome ..
Last 5 posts in Google
- Google Webmaster Tools Offers Notifications for Hacking and Abuse - March 3rd, 2010
- Cooliris – Multi-browser Add-ons For Amazing 3D Wall of Images and Video Effects - February 23rd, 2010
- The First Buzz Extension Buzz it ! –Google Buzz Firefox Add-ons for Mozilla Firefox - February 13th, 2010
- Google Chrome For Linux and Chrome for Mac available for Download - December 12th, 2009
- The History and present of Google in a Nicely Presented Video - October 26th, 2009


Leave a Reply