-
-
Just after recent controversial privacy issue with Google Chrome browser there is old Webkit vulnerability haunting this new slick Google browser. There no official patch from the Chromium developer yet but it seem like bugs inheritance is something you should be aware of. Because Google Chrome browser is partially a Safari 3.1 with different architecture without JavascriptCore (script parse with Google open source javascript V8 Engine).Current Chrome (beta) is based on WebKit 525.13 (Safari 3.1) rendering engine and introduces many of features inspired/taken from different modern browser (including some vulnerabilities). Theoretically any previous vulnerability in AppleWebkit/Safari 3.1 is shared by Chrome users.

Workaround for Google Chrome Carpet Bombing vulnerability
As expected from previous Safari ticket on this vulnerabilty, both Safari & Chrome developer label this as non vulnerability threat so there no fixes/patch (aka WontFix) for this particular issue. Blame it on interface design.
The below guide is simple workaround for Chrome Carpet Bombing vulnerability (#897 : Automatic file download without confirmation possible) . Basically just disabled the auto save file to desktop by default.
- Click on the “Tools wrench icon”
and select Options. - On the Options windows select the “Minor Tweaks” tab.
- Then checked the “Ask where to save each file before downloading” check box.
- Close the options windows. end
Chromium team should enabled the above options by default. That would prevent malicious attack. It’s not very exciting to see all of this happening within short time periods.
Related External Links
- Click on the “Tools wrench icon”
-
3 Responsesto “Workaround for Google Chrome Automatic file download vulnerability”
it’s funny, the more i use Chrome (for windows), the more unstable it seems to get… crashes a lot more, can’t handle sites with flash, hangs every time i close a tab… all that to say, i’m switching back to Firefox
[Reply]Yes exactly, especially at You Tube or while using any FLV players. Chrome doesn’t handle flash very well. It usually stuck when you try dragging the fast-forward scroller.
They are making Chrome beta as bug hunting fest. Just hope it wont be beta “like forever” (gmail). I would wait until chromium guys release version 1 or till they get their hands on add-ons & extensions.
[Reply]good resourse Anyway by sight very much it is pleasant to me
[Reply]If you want to comment, please read the following guidelines. These are designed to protect you and other users of the site.
In order to keep these experiences enjoyable and interesting for all of our users, we ask that you follow the above guidlines. Feel free to engage, ask questions, and tell us what you are thinking! insightful comments are most welcomed.
Subscribe to this discussion via RSS
Taxonomy
Most used terms