Quote - (Harsesis @ Sep 3 2008, 23:54)

Its using the old version of webkit... there is a newer version that this bug is fixed on.
Its the carpet bomb bug people were going crazy about before.
first this has nothing to do with WebKit the
rendering engine. WebKit does not handle file downloads. It's the UI shell that decides what to do with a file that the rendering engine don't understand (ie. not web pages).
Second, back when Safari
the browser had the carpet bombing exploit, there was no option to stop that. All downloads are automatically with no option to change that. For Chrome just go to Options -> Minor Tweaks -> check "Ask where to save each file before downloading", and you'll be prompted every time a download start.
Quote - (mocax @ Sep 4 2008, 00:15)

damn, I was about to test incognito on porn sites
I'll hold off for a while, until they fix it.
well, you can "fix" it yourself, by enabled an option in the Options menu.
Quote - (SOOPRcow @ Sep 4 2008, 00:31)

It doesn't say the exe is being executed, it is just being downloaded so some user interaction is still required. Don't get me wrong though, I understand how serious of an issue it is.
well combined with an exploit in Windows (which I'm not sure if it's still there) or Java, the downloaded file can be automatically executed.
Quote - (tsupersonic @ Sep 4 2008, 21:32)

You'd think Google would've fixed the EXE flaw before releasing this, it's a damn big security hole.
well, I guess Google expected that anyone who wanted to fix it can fix it themselves, by ticking a checkbox in the Options menu.