Recommended Posts

Did we already not know this? I mean it's beta, it's going to have gaping flaws everywhere. It's still a little stupid to release something with such a huge hole though. More like irresponsible considering this is Google, right? Because when they mess up, it's cool. When others mess up it's a media frenzy.

I don't think this is going to be easy for Google by any means. Other browsers are better Maxthon, IE, Firefox, Opera..why the huge fuss over this? Those browsers do everything and more so why would I take a step back? My two cents. It will probably take years before it makes it out of Beta. :D

Did we already not know this? I mean it's beta, it's going to have gaping flaws everywhere. It's still a little stupid to release something with such a huge hole though. More like irresponsible considering this is Google, right? Because when they mess up, it's cool. When others mess up it's a media frenzy.

I don't think this is going to be easy for Google by any means. Other browsers are better Maxthon, IE, Firefox, Opera..why the huge fuss over this? Those browsers do everything and more so why would I take a step back? My two cents. It will probably take years before it makes it out of Beta. :D

i dont recall any of the browser having such bugs that it seems like they were done in purpose, cmon now, how dumb do you have to be to make the things that it does happen. my guess is dumb as google (which is pretty high up the scale.)

This isn't exactly a huge problem, and in fact I'd prefer if google DIDN'T fix it.

The "problem" is that google auto-downloads any file type, rather than popping up copious security warnings like IE does. It's not a serious security problem because it still requires one mouse click to actually run that exe file.

Remember that a malicious file on your PC does no harm as long as it isn't executed, and in this case it requires an explicit mouse click on the chrome gui to make it run, which is just the way it should be.

i like chrome personally,.. but just type :% in the address bar and your entire browser will crash

but i still like chrome

Confirmed on that, wonder what about that makes it crash.

I'm also going into withdrawal anytime I use Chrome for some mouse gestures. I think browsers should have those built in now because they're so handy.

So let me get this right. Everyone is going crazy because the browser expects people to have common sense and click for themselves if they want to execute an exe or not? omg please someone call the webpolice.

And the thing that they are allowed to post anything you surf to on the internet is probably so they are able to debug things if they happen. Not to mention google likes playing with ads so could be related to that. I doubt they are going to post your 50 porn sites you surf to a day on the front page of google.

This isn't exactly a huge problem, and in fact I'd prefer if google DIDN'T fix it.

The "problem" is that google auto-downloads any file type, rather than popping up copious security warnings like IE does. It's not a serious security problem because it still requires one mouse click to actually run that exe file.

Remember that a malicious file on your PC does no harm as long as it isn't executed, and in this case it requires an explicit mouse click on the chrome gui to make it run, which is just the way it should be.

So let me get this right. Everyone is going crazy because the browser expects people to have common sense and click for themselves if they want to execute an exe or not? omg please someone call the webpolice.

You're missing the point entirely. Browsers should run in a sandboxed environment owing to the nature of the web; allowing files of any kind to be saved to the user's machine without their consent (outside of the designated areas for cookies etc.) is a security flaw and I fail to see how you can think otherwise.

You're missing the point entirely. Browsers should run in a sandboxed environment owing to the nature of the web; allowing files of any kind to be saved to the user's machine without their consent (outside of the designated areas for cookies etc.) is a security flaw and I fail to see how you can think otherwise.

Hmm I was replying to the fact Chrome does not refuse exe files but opens a dialog box to check if you want to execute it. To me there is nothing wrong with that.

Which of all these is it? Because I like info on the internet... everyone goes crazy and starts throwing stuff everywhere. Someone in this topic says they execute it without warning, another says they open a dialog box another says they download it without warning without executing it...

Also it's a beta, there have been much bigger flaws in live versions from for example IE.

Hmm I was replying to the fact Chrome does not refuse exe files but opens a dialog box to check if you want to execute it. To me there is nothing wrong with that.

Which of all these is it? Because I like info on the internet... everyone goes crazy and starts throwing stuff everywhere. Someone in this topic says they execute it without warning, another says they open a dialog box another says they download it without warning without executing it...

Also it's a beta, there have been much bigger flaws in live versions from for example IE.

Ah, we're talking about different things:

The issue is that with iframes the file can be downloaded onto the desktop of the user. Without any prompts whatsoever. Yes, it won't be opened, but the mere fact that anything is automatically downloaded, particularly an executable file, is a security risk. It's not that I, or the original poster, is suggesting EXE files should be blocked: it's that without any user interaction whatsoever I could construct a page that downloaded twenty EXE files onto the user's desktop, just by visiting. That's poor.

its funny how people react to some lame sentence in terms of service.

I'll say... it's as if all these people think they're going to publish some world-changing thesis paper and Google's going to steal it cause they used Chrome.

I think it's funny how paranoid and ignorant everyone is.

I'll say... it's as if all these people think they're going to publish some world-changing thesis paper and Google's going to steal it cause they used Chrome.

I think it's funny how paranoid and ignorant everyone is.

IMO it's more than that. If they can apparently have control of what you post when using Chrome...how can they tell that you're using Chrome? Do the log keystrokes or something?

Its using the old version of webkit... there is a newer version that this bug is fixed on.

Its the carpet bomb bug people were going crazy about before.

first this has nothing to do with WebKit the rendering engine. WebKit does not handle file downloads. It's the UI shell that decides what to do with a file that the rendering engine don't understand (ie. not web pages).

Second, back when Safari the browser had the carpet bombing exploit, there was no option to stop that. All downloads are automatically with no option to change that. For Chrome just go to Options -> Minor Tweaks -> check "Ask where to save each file before downloading", and you'll be prompted every time a download start.

damn, I was about to test incognito on porn sites

I'll hold off for a while, until they fix it.

well, you can "fix" it yourself, by enabled an option in the Options menu.

It doesn't say the exe is being executed, it is just being downloaded so some user interaction is still required. Don't get me wrong though, I understand how serious of an issue it is.

well combined with an exploit in Windows (which I'm not sure if it's still there) or Java, the downloaded file can be automatically executed.

You'd think Google would've fixed the EXE flaw before releasing this, it's a damn big security hole.

well, I guess Google expected that anyone who wanted to fix it can fix it themselves, by ticking a checkbox in the Options menu. :laugh:

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • A few years ago walmart had the 512 models on clearance for $35. I bought 3 of them. I should have purchased more.
    • I'm fine with a little reasonable promotion of Edge, but the degree which they do it right now I consider extremely unreasonable. 
    • Microsoft AI boss no longer believes that AI will replace human workers by David Uzondu Mustafa Suleyman, the head of Microsoft AI, recently took back his statements concerning white-collar jobs that he gave to the Financial Times in an interview made back in February, where he claimed that AI would replace office workers within 12 to 18 months. On Monday's episode of The Verge's Decoder, Suleyman recast the technology as more like a helpmate than a tool designed to take over your job. He explained that smaller office duties will "increasingly become digitized, automated" as people generate more digital materials. During the discussion, Suleyman emphasized a "very important distinction" between "tasks" and "jobs" to clarify his previous claims. He argued that his earlier comments only referred to individual actions that people perform at their desks. Suleyman used to work for DeepMind, the research lab he co-founded in 2010 alongside Demis Hassabis and Shane Legg, before he left in 2022 to establish Inflection AI and build an empathetic digital assistant. Microsoft hired him in March 2024 to lead its newly formed "Microsoft AI" division, placing him in charge of consumer products like Copilot, Bing, and Edge. His February comments also detailed plans for Microsoft to achieve self-sufficiency with a $140 billion infrastructure budget to train frontier models, predicting that creating a customized AI will soon feel like creating a podcast or a new blog: The 41-year-old is not the only AI executive who's softened his "AI will replace you" stance. OpenAI's CEO, Sam Altman, last month used X to push back against employment panic by arguing that his startup builds tools to assist humans rather than build replacements. He had previously garnered backlash by suggesting that many modern office roles that AI might replace did not qualify as "real work" in the first place, at least when you compare desk jobs to physical, historical labor like farming.
    • Adobe Acrobat Reader DC 2026.001.21662 by Razvan Serea Adobe Acrobat Reader DC software is the free, trusted standard for viewing, printing, signing, and annotating PDFs. Its the only PDF viewer that can open and interact with all types of PDF content – including forms and multimedia. It’s connected to Adobe Document Cloud – so you can work with PDFs on computers and mobile devices. Adobe Document Cloud is a revolutionary, modern and efficient way to get work done with documents in the office, at home or on-the-go. At the heart of Document Cloud is the all-new Adobe Acrobat DC, which will take e-signatures mainstream by delivering free e-signing with every individual subscription. Document Cloud includes a set of integrated services that use a consistent online profile and personal document hub. With Adobe Document Cloud, people will be able to create, review, approve, sign and track documents whether on a desktop or mobile device. Businesses will be able to take advantage of Document Cloud for enterprise which provides enterprise-class document services that integrate into systems of record such as CRM, HCM, CLM, and CMS, adding speed, efficiency and transparency to getting business done with documents. Adobe Acrobat Reader DC new feature highlights: Work with PDFs from anywhere with the new, free Acrobat DC mobile app for Android or iOS. Select functionality is also available on Windows Phone. Use the new Fill & Sign tool in your desktop software to complete PDF forms fast with smart autofill. Download the free Adobe Fill & Sign mobile app to add the same option to your iPad or Android tablet device. Save money on ink and toner when printing from your Windows PC. Store and access files in Adobe Document Cloud with 5GB of free storage. Get instant access to recent files across desktop, web, and mobile devices with Mobile Link. Sync your Fill & Sign autofill collection across desktop, web, and iPad devices. Adobe PDF Pack premium features includes: Convert documents and images to PDF files. Use your mobile device camera to take a picture of a paper document or form and convert it to PDF. Turn PDFs into editable Microsoft Word, Excel, PowerPoint, or RTF files. Combine multiple files into a single PDF (web only). Get signatures from others with a complete e-signature service. Send, track, and confirm delivery of documents electronically instead of using fax or overnight services (tracking not available on mobile). Store and access files online with 20GB of storage. Download: Adobe Acrobat Reader DC 64-bit | 719.0 MB (Freeware) Link: Adobe Acrobat Reader DC Home Page | Release Notes | Screenshot Get alerted to all of our Software updates on Twitter at @NeowinSoftware
    • Meta will now use data from outside businesses to personalize AI responses by David Uzondu In an update that's rolling out globally (except in a handful of countries), Meta will use your data from outside businesses to personalize your AI responses and your primary feeds. Meta already utilizes your shopping activity to target ads, but the company now plans to expand this tracking to personalize other "parts of your experience" like feed algorithms and AI assistant chats. The company is replacing the two settings ("Your activity off Meta technologies" and "Activity from other businesses") that currently let you disconnect off-platform activity with a single, renamed setting called Activity from other businesses. If you don't want Meta to manipulate your feed and AI responses using your outside history, you can just turn the Activity from other businesses setting off in your account settings. This toggle resides within your Accounts Center, applying your choice to every connected profile. Turning this off will not stop companies from sending your data to Meta. The company will still collect your web interactions, but it only uses them to train products, while still accessing external accounts you connect. When The Verge spoke to Meta spokesperson Emil Vazquez, the representative said that this update will exclude several locations at launch, including the European region, the UK, Brazil, Thailand, South Africa, Turkey, South Korea, Ecuador, Nigeria, and Kenya. The new update comes at a time when the social media giant is recovering from a major PR disaster involving generative AI. Last week, there was a huge security issue on Instagram where attackers figured out a way to trick Meta AI into handing over account ownership (even if the victim had 2FA enabled). Some of the affected accounts include the dormant Obama White House profile, cosmetics brand Sephora, the Chief Master Sergeant of the Space Force, and security researcher Jane Manchun Wong. Internally, the company also had to scale back plans on its Model Capability Initiative (MCI), an employee-monitoring program designed to train corporate AI models by recording worker keystrokes and screen activity, after employees raised privacy concerns and complained about severe battery life drain.
  • Recent Achievements

    • One Year In
      Primer1st earned a badge
      One Year In
    • Experienced
      JayZJay went up a rank
      Experienced
    • Reacting Well
      Sir_Timbit earned a badge
      Reacting Well
    • Week One Done
      rubentuben8 earned a badge
      Week One Done
    • Week One Done
      ARaclen earned a badge
      Week One Done
  • Popular Contributors

    1. 1
      +primortal
      512
    2. 2
      PsYcHoKiLLa
      229
    3. 3
      Edouard
      134
    4. 4
      ATLien_0
      87
    5. 5
      Steven P.
      80
  • Tell a friend

    Love Neowin? Tell a friend!