Google Chrome Browser Vulnerable to Security Flaw

Google Chrome Browser Vulnerable to Security Flaw

Written By
Brian Prince
Brian Prince
Sep 3, 2008
1 minute read
eWeek content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

A security researcher has discovered a flaw in the beta version of Google’s Chrome browser that can lead to Windows users downloading malicious Java files.

According to the ZDNET security blog, Israeli security researcher Aviv Raff has released proof-of-concept code that targets a vulnerability in an old version of WebKit being used by the Google browser as well as a Java bug. With a little social engineering, users can be tricked into downloading malware onto Windows desktops.

For eWEEK’s review of Google Chrome, click here.

Ironically, the WebKit flaw this targets was patched already by Apple. Raff has created a demonstration for the flaw that will download a Java Archive file onto a user’s desktop that gets executed without warning. Once the user double-clicks the download at the bottom of the screen, the application is opened.

The demonstration, available here, reportedly opens up a harmless notepad application written in Java.

News of the flaw Sept. 2 came only hours after Google publicly launched the beta for its new browser and stressed security was a main focus. The browser has a number of features designed to protect users, including a private browsing mode known as “Incognito” and the sandboxing of the rendering engine. Google also leverages blacklists to protect users from known rogue sites.

eWeek Logo

eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site's focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.