Technology|August 7, 2011 11:25 am

WhiteHat Security hacks into Chrome OS, exposes extension vulnerability at Black Hat

It’s been a severe Black Hat discussion for Google. First, FusionX used a company’s homepage to examine in to a horde of SCADA systems, as good as now, a span of experts have detected a approach to penetrate in to Chrome OS. According to WhiteHat confidence researchers Matt Johansen as good as Kyle Osborn, a single vital emanate is Google’s vet-free app capitulation process, which leaves a Chrome Web Store receptive to antagonistic extensions. But there have been additionally vulnerabilities inside of local extensions, identical to ScratchPad — a note-taking prolongation which stores interpretation in Google Docs. Using a cross-site scripting injection, Johansen as good as Osborn were means to take a user’s contacts as good as cookies, which could give hackers entrance to alternative accounts, together with Gmail. Big G fast patched a hole after WhiteHat unclosed it progressing this year, though researchers told Black Hat’s attendees which they’ve detected identical vulnerabilities in alternative extensions, as well. In a statement, a Google orator said, “This review is about a Web, not Chrome OS. Chromebooks lift confidence protections upon computing hardware to latest levels.” The association went upon to contend which a laptops can sentinel off attacks improved than most, interjection to “a delicately written extensions indication as good as a modernized confidence accessible by Chrome which most users as good as experts have embraced.”

Affiliate Banner
  • Share this post:
  • Facebook
  • Twitter
  • Delicious
  • Digg