Recommended Posts

Did we already not know this? I mean it's beta, it's going to have gaping flaws everywhere. It's still a little stupid to release something with such a huge hole though. More like irresponsible considering this is Google, right? Because when they mess up, it's cool. When others mess up it's a media frenzy.

I don't think this is going to be easy for Google by any means. Other browsers are better Maxthon, IE, Firefox, Opera..why the huge fuss over this? Those browsers do everything and more so why would I take a step back? My two cents. It will probably take years before it makes it out of Beta. :D

Did we already not know this? I mean it's beta, it's going to have gaping flaws everywhere. It's still a little stupid to release something with such a huge hole though. More like irresponsible considering this is Google, right? Because when they mess up, it's cool. When others mess up it's a media frenzy.

I don't think this is going to be easy for Google by any means. Other browsers are better Maxthon, IE, Firefox, Opera..why the huge fuss over this? Those browsers do everything and more so why would I take a step back? My two cents. It will probably take years before it makes it out of Beta. :D

i dont recall any of the browser having such bugs that it seems like they were done in purpose, cmon now, how dumb do you have to be to make the things that it does happen. my guess is dumb as google (which is pretty high up the scale.)

This isn't exactly a huge problem, and in fact I'd prefer if google DIDN'T fix it.

The "problem" is that google auto-downloads any file type, rather than popping up copious security warnings like IE does. It's not a serious security problem because it still requires one mouse click to actually run that exe file.

Remember that a malicious file on your PC does no harm as long as it isn't executed, and in this case it requires an explicit mouse click on the chrome gui to make it run, which is just the way it should be.

i like chrome personally,.. but just type :% in the address bar and your entire browser will crash

but i still like chrome

Confirmed on that, wonder what about that makes it crash.

I'm also going into withdrawal anytime I use Chrome for some mouse gestures. I think browsers should have those built in now because they're so handy.

So let me get this right. Everyone is going crazy because the browser expects people to have common sense and click for themselves if they want to execute an exe or not? omg please someone call the webpolice.

And the thing that they are allowed to post anything you surf to on the internet is probably so they are able to debug things if they happen. Not to mention google likes playing with ads so could be related to that. I doubt they are going to post your 50 porn sites you surf to a day on the front page of google.

This isn't exactly a huge problem, and in fact I'd prefer if google DIDN'T fix it.

The "problem" is that google auto-downloads any file type, rather than popping up copious security warnings like IE does. It's not a serious security problem because it still requires one mouse click to actually run that exe file.

Remember that a malicious file on your PC does no harm as long as it isn't executed, and in this case it requires an explicit mouse click on the chrome gui to make it run, which is just the way it should be.

So let me get this right. Everyone is going crazy because the browser expects people to have common sense and click for themselves if they want to execute an exe or not? omg please someone call the webpolice.

You're missing the point entirely. Browsers should run in a sandboxed environment owing to the nature of the web; allowing files of any kind to be saved to the user's machine without their consent (outside of the designated areas for cookies etc.) is a security flaw and I fail to see how you can think otherwise.

You're missing the point entirely. Browsers should run in a sandboxed environment owing to the nature of the web; allowing files of any kind to be saved to the user's machine without their consent (outside of the designated areas for cookies etc.) is a security flaw and I fail to see how you can think otherwise.

Hmm I was replying to the fact Chrome does not refuse exe files but opens a dialog box to check if you want to execute it. To me there is nothing wrong with that.

Which of all these is it? Because I like info on the internet... everyone goes crazy and starts throwing stuff everywhere. Someone in this topic says they execute it without warning, another says they open a dialog box another says they download it without warning without executing it...

Also it's a beta, there have been much bigger flaws in live versions from for example IE.

Hmm I was replying to the fact Chrome does not refuse exe files but opens a dialog box to check if you want to execute it. To me there is nothing wrong with that.

Which of all these is it? Because I like info on the internet... everyone goes crazy and starts throwing stuff everywhere. Someone in this topic says they execute it without warning, another says they open a dialog box another says they download it without warning without executing it...

Also it's a beta, there have been much bigger flaws in live versions from for example IE.

Ah, we're talking about different things:

The issue is that with iframes the file can be downloaded onto the desktop of the user. Without any prompts whatsoever. Yes, it won't be opened, but the mere fact that anything is automatically downloaded, particularly an executable file, is a security risk. It's not that I, or the original poster, is suggesting EXE files should be blocked: it's that without any user interaction whatsoever I could construct a page that downloaded twenty EXE files onto the user's desktop, just by visiting. That's poor.

its funny how people react to some lame sentence in terms of service.

I'll say... it's as if all these people think they're going to publish some world-changing thesis paper and Google's going to steal it cause they used Chrome.

I think it's funny how paranoid and ignorant everyone is.

I'll say... it's as if all these people think they're going to publish some world-changing thesis paper and Google's going to steal it cause they used Chrome.

I think it's funny how paranoid and ignorant everyone is.

IMO it's more than that. If they can apparently have control of what you post when using Chrome...how can they tell that you're using Chrome? Do the log keystrokes or something?

Its using the old version of webkit... there is a newer version that this bug is fixed on.

Its the carpet bomb bug people were going crazy about before.

first this has nothing to do with WebKit the rendering engine. WebKit does not handle file downloads. It's the UI shell that decides what to do with a file that the rendering engine don't understand (ie. not web pages).

Second, back when Safari the browser had the carpet bombing exploit, there was no option to stop that. All downloads are automatically with no option to change that. For Chrome just go to Options -> Minor Tweaks -> check "Ask where to save each file before downloading", and you'll be prompted every time a download start.

damn, I was about to test incognito on porn sites

I'll hold off for a while, until they fix it.

well, you can "fix" it yourself, by enabled an option in the Options menu.

It doesn't say the exe is being executed, it is just being downloaded so some user interaction is still required. Don't get me wrong though, I understand how serious of an issue it is.

well combined with an exploit in Windows (which I'm not sure if it's still there) or Java, the downloaded file can be automatically executed.

You'd think Google would've fixed the EXE flaw before releasing this, it's a damn big security hole.

well, I guess Google expected that anyone who wanted to fix it can fix it themselves, by ticking a checkbox in the Options menu. :laugh:

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • Apple is expanding Private Cloud Compute beyond its own data centers by Pradeep Viswanathan At WWDC 2026, as part of the improved Apple Intelligence capabilities, Apple today announced that it is expanding Private Cloud Compute (PCC), its privacy-focused cloud infrastructure for Apple Intelligence, beyond its own data centers for the first time. Private Cloud Compute was designed to handle Apple Intelligence requests that are too complex to run fully on-device. The PCC system does not store user data and does not allow Apple or anyone else to access user requests. Last year, Apple also expanded its Security Bounty program with rewards of up to $1 million for researchers who could find serious vulnerabilities in PCC. Until now, Apple's PCC data centers were using Apple's own silicon. As part of the expansion, Apple is working with Google and NVIDIA to run new Apple Intelligence workloads on Google Cloud systems powered by NVIDIA GPUs. Apple will be using this new infrastructure to execute more demanding AI tasks while maintaining the same privacy and security guarantees of PCC. The new implementation uses NVIDIA Confidential Computing with NVIDIA GPUs, Intel CPUs with TDX, and Google’s Titan chip. Apple says it has worked with Google to build additional protections beyond a traditional confidential computing deployment. Despite the expansion to third-party data centers, Apple claims that its core PCC requirements remain unchanged, including stateless computation, no privileged runtime access, non-targetability, and verifiable transparency. The company highlighted that it will continue to control the PCC software stack, and Apple devices will only trust PCC software that has been cryptographically approved by Apple. To take security to the next level, Apple mentioned that it is maintaining an append-only ledger of Google Cloud hardware that is part of the PCC fleet. The company claims this will help reduce the risk of supply chain attacks. In addition to AI infrastructure, Apple also worked with Google to use technologies behind the Gemini family of models to build the next generation of Apple Foundation Models to power Apple Intelligence features across on-device and cloud workloads. As expected, for more demanding AI tasks like agentic tool use and complex reasoning, Apple will rely on the expanded PCC infrastructure running on Google Cloud. The expansion of PCC on Google Cloud will gradually ramp toward the full set of protections during the summer preview period. As before, Apple will also publish binaries for public inspection, provide research tooling, and give researchers access to live PCC nodes in research mode through the Apple Security Bounty Program.
    • my problem with outlook (new) is that it connects only to outlook.com. all connections to external providers goes through there. Got your mail server and want to use imap directly? no way... it adds a connector on outlook.com. last bug; if your email on an external provider if the same as principal email of your microsoft account, it doesn't work...
    • It's the only reason I finally have an iPhone (for work) and enjoy using it so much that I'm tempted to move from android next time I need to replace my own device
    • So is Russia, China, Iran, North Korea, just to mention a few. What's your point? Everyone is a threat from their enemies' perspective. I'd say that Israel is only a threat to their immediate enemies like Hamas, Hezbollah and the Iranian regime, not to anyone else.
    • The government is not the good guy either. You propose 99% of people require that the government overreach and govern their freedom of information and privacy, while ignoring the government is made up 100% of people, of which 99% are (as you described) brain dead. You can't have both. The reality is Signal is absolutely right and the government is doing what it has always done. Ignoring that we are their boss and grabbing all the power they possibly can to make sure we aren't. Your (societies) ###### parenting is not reason enough as to why I can't have a safe platform for my data/information. Thinking the government is helping is precisely what they are targeting psychologically to take suckers like you for a ride. "Think of the children" was, has, is, and will always be a mechanism of control. In the rare occasion it's actually essential the mass consensus has always been there and it doesn't become a debate.
  • Recent Achievements

    • Very Popular
      Captain_Eric earned a badge
      Very Popular
    • One Month Later
      amusc earned a badge
      One Month Later
    • One Month Later
      DJC50PLUS earned a badge
      One Month Later
    • Week One Done
      DJC50PLUS earned a badge
      Week One Done
    • Proficient
      Eric Biran went up a rank
      Proficient
  • Popular Contributors

    1. 1
      +primortal
      509
    2. 2
      PsYcHoKiLLa
      222
    3. 3
      ATLien_0
      92
    4. 4
      +Edouard
      86
    5. 5
      Steven P.
      81
  • Tell a friend

    Love Neowin? Tell a friend!