Google Chrome, Internet Explorer Caught in Vulnerability Web | eWeek

Google Chrome, Internet Explorer Caught in Vulnerability Web

Written By
Brian Prince
Brian Prince
Apr 27, 2009
1 minute read
eWeek content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

The Google Chrome Web browser and Microsoft Internet Explorer have found themselves at the center of a security issue that could lead to cross-site scripting attacks.

Google Chrome has been updated to 1.0.154.59 to fix a security vulnerability in the handling of ChromeHTML URIs (Uniform Resource Identifiers) that allows an attacker to bypass the Same Origin Policy for any site and enumerate victim’s files and directories.

According to an advisory from Google, the issue permits universal cross-site scripting without user interaction.

“If a user has Google Chrome installed, visiting an attacker-controlled Web page in Internet Explorer could have caused Google Chrome to launch, open multiple tabs and load scripts that run after navigating to a URL of the attacker’s choice,” the advisory stated.

The vulnerability was discovered by IBM security researcher Roi Saltzman, who noted in a blog post that the processing of URL protocol handlers has been an ongoing issue with Internet Explorer. A similar situation was uncovered in 2007 involving Internet Explorer and Firefox.

“These issues pose a major threat to any user that browses a maliciously crafted page using Internet Explorer and has Google Chrome installed alongside,” Saltzman wrote. “It is important to note that the way Internet Explorer processes URL protocol handlers is a known Achilles’ heel and has been widely used previously to attack other various applications.”

A more detailed advisory can be downloaded off the IBM Rational Application Security Insider blog.

eWeek Logo

eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site's focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.