Critical Google Chrome hole plugged in 24 hours
arstechnica.com
arstechnica.com
I notice that pretty much every time I read articles about Pwn2Own and similar. It's high time that Flash was abandoned as a ubiquitous part of the web. It is to web development as Outlook Express was to desktop software in the 90s - sure it's everywhere, but it's not doing much good by being so.
If anybody else is looking, this can be done (without addons) under:
[Wrench] > Settings > "Under the Bonnet" Advanced Settings > "Privacy" Content Settings > Scroll down to "Plugins" and select "Click to Play". Manage exceptions as required.
I used to use Flashblock with Chrome but this works just as well, not to mention being built in. I use this setting on my CR-48 (Chromebook).
And that the SVN commit history is available: http://build.chromium.org/f/chromium/perf/dashboard/ui/chang...
But I don't see any commit that look even remotely related to this exploit. What's up?
-- a change to kUnreachableWebDataURL
By committing the fix, they would effectively be releasing a step-by-step guide on how to exploit the vulnerability.
Certainly if you build Chromium from git/SVN now, the bug is fixed.
I just find it a little strange that their changelog / list of commits in each version is not true.
I don't think it's a good argument - what about defense in depth? Don't antivirus packages have heuristic protections? Or are those, in general, useless?
The cases I've read about were of the form "app A asks app B to do something it can't via the Intent system". That sounds scary until you realize that a standard example of this is an app that can't access the network sharing something via email. In other words, app A has transferred control to app B and what the user does (or doesn't) decide to do with app B is their choice, not app A's.
Which leads me to the question: why aren't companies like Google customers of companies like Vupen? Too many of them to make it cost-effective? Or does Vupen (for example) prefer if those holes are not fixed? You can sell a vulnerability many times, after all.
A patched vulnerability would not be worth nearly as much to them and their customers.
P.S. Vupen sells to ASEAN. ASEAN includes Burma (Myanmar). Burma is not a happy place.