Geek Out!

live.pirillo.com

More Information

Microsoft finds security flaw in Google Chrome Frame

Back in September, when Google launched the Google Chome Frame plug-in for Internet Explorer users, Microsoft immediately warned that the move would increase the attack surface and make IE users less secure.

Now comes word that a security researcher in the Microsoft Vulnerability Research (MSVR) has discovered a "high risk" security vulnerability that could allow an attacker to bypass cross-origin protections.
Here's the explanation from Google's Matt Larson:

* Severity: High. An attacker could have bypassed cross-origin protections. Although important, "High" severity issues do not permit persistent malware to infect a user's machine. We're unaware of any exploitation of this issue.

The search technology company has shipped a new version of the Google Chrome Frame (version 4.0.245.1) with a patch for the vulnerability.

The plug-in update also fixes several bugs:

* Network requests fail randomly.
* Fix issues with CFInstall.js to better detect compatible OS and browser versions, allow users to cancel the installation frame, and not cache the isAvailable result.
* Don't use Google Chrome Frame for frames or iframes.
* Follow redirects properly.
* IE8 freezing intermittently.
* Remove data directories on uninstall.

"All users should be updated automatically," Larson said.

More information can be found at http://googlechromereleases.blogspot.com/2009/11/google-chrome-fram...

Views: 6

Comment

You need to be a member of Geeks to add comments!

Join Geeks

© 2012   Created by Chris Pirillo.

Badges  |  Report an Issue  |  Terms of Service