Chrome Vulnerable To Hackers, Says Researcher

A Combination Of Factors, Including Extensions, Give The Chrome System Unusual Vulnerability In Tests

New research emerges today showing that the Chrome operating system may have some serious flaws on its hands that leave it unusually open to being hacked.

Matt Johansen out of WhiteHat Security started dropping the word on this one, saying that there was a flaw with an application in Chrome, which in turn let him seize control of a Google email account. Google, for its part, responded to the news of the flaw in rapid fashion and fixed it, but the WhiteHat Security researcher found other instances of the same flaw in other applications soon after.

The problem, based on reports, seems to revolve around Chrome’s use of extensions that can be downloaded from the Google Chrome Web Store, which in turn may allow hackers access to data that passes between a user’s system running Chrome and anything in a cloud storage due to the way Chrome treats an extension’s rights to access data.

Google, for its part, acknowledges the first issue with the extension that they repaired, but takes some issue with calling Chrome a “vulnerable” operating system over its use of extensions. Though in all honesty, I’m not seeing that to be the problem so much as the way some extensions work. It’s not that Chrome uses extensions, but that some extensions go a little too far when it comes to granting access to cloud storage data. Indeed, WhiteHat was quick to point out that it works with Google on a regular basis, and wasn’t trying to issue some kind of challenge to Google, just point out a possible flaw in the system, especially with regards to cloud storage, that could stand some addressing.

I find myself wondering if this will affect the way people regard the Chrome OS, and possibly dissuade some from using it. Chrome’s penetration into a marketplace already deeply entrenched by Microsoft and Apple, though, may prove a bit problematic to begin with, so they don’t need more issues. So I’ll open it up to you guys.

Do you think these potential issues will dissuade some possible Chrome users? Or do you think those who would use Chrome anyway probably already know about the security challenges in question? We always like hearing from you, so head on down to the comments section and tell us what you think!

Related Stories on TFTS:
  • New iPad Smuggling No Longer a Successful Business?

    A Number of Factors Including Increased iPad 3 Production Help Apple Fight iPad Smuggling to China & Other Markets

  • USB Drive Uses Unusual Method For A Password

    Upscale Geek Boutique Hammacher Schlemmer's New USB Drive Uses Unusual Means To Protect Its Data Content From Potential Thieves

  • Cadillac Puts Self Driving Super Cruise System In Road Tests

    Cadillac's Attempt At Self-Driving Cars May Hit Wide Release Soon, Cutting Off Google

  • MWC 2012: Skype For Windows Phone Reveals Unexpected Limitation

    Reports Of Early Tests With Skype For Windows Phone Reveal An Unexpected Flaw In The System Current Skype Users Will Likely Notice

  • LG LS831 Gets Outed By The FCC

    FCC Drops Some Information On LG's Upcoming LS831 Phone, Including Its Operating System & Carrier Of Choice



  • 1 Comment / Add Your Response?

    1. david says:

      The writer fails to look at the bigger picture and the degree of risk posed by the windows operating system and its many security challenges.