Chrome exploits

Google Chrome Browser 0.2.149.27 Automatic File Download Exploit sourced from milw0rm

Summary:
  • A naughty website can include the code shown in the exploit, in order to automatically download any file they like to your computer.
  • The file will be downloaded to the default location (in Windows: My Documents\Downloads\)
  • This is not necessarily a risk if you do not run the file, but it is troubling nonetheless
In a related note, I wonder why Chrome does not include a master password to encrypt saved passwords. Anyone using your computer can just open Chrome options and see all your saved passwords. Yes it's beta, but this seems pretty important to include early on.

Definitely enjoying using Chrome on [safe] websites!

No comments:

Post a Comment