<?xml version="1.0" encoding="utf-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" 
      xmlns:thr="http://purl.org/syndication/thread/1.0">
  <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/time_to_patch_google_chrome.php" />
  <link rel="self" type="application/atom+xml" href="http://www.readwriteweb.com/atom.xml" />
  <id>tag:www.readwriteweb.com,2011:/1/tag:www.readwriteweb.com,2009://1.14806-</id>
  <updated>2011-08-16T17:23:46Z</updated>
  <title>Comments for Uh-oh! Time to Patch Google Chrome</title>
  
  <generator uri="http://www.sixapart.com/movabletype/">Movable Type 4.35-en</generator>
  <entry>
    <id>tag:www.readwriteweb.com,2009://1.14806</id>
    <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/time_to_patch_google_chrome.php" />
    <link rel="service.edit" type="application/atom+xml" href="http://www.readwriteweb.com/cgi-bin/mt/mt-atom.cgi/weblog/blog_id=1/entry_id=14806" title="Uh-oh! Time to Patch Google Chrome" />
    <published>2009-04-27T14:26:46Z</published>
    <updated>2009-04-27T19:14:19Z</updated>
    <title>Uh-oh! Time to Patch Google Chrome</title>
    <summary>Earlier this month, a problem was discovered in Google&apos;s new web browser, Google Chrome, that would have allowed an attacker to launch and run scripts on a compromised machine. The issue, originally discovered by Roi Saltzman of the IBM Rational Application Security Research Group, had been given a security rating of &quot;high.&quot; Interestingly enough, although...</summary>
    <author>
      <name>Sarah Perez</name>
      
    </author>
    
    <category term="Google" />
    
    <category term="News" />
    
    <content type="html" xml:lang="en" xml:base="http://www.readwriteweb.com/">
      <![CDATA[<p><img src="http://www.readwriteweb.com/images/google_chrome.jpg">Earlier this month, a <a href="http://code.google.com/p/chromium/issues/detail?id=9860">problem</a> was discovered in Google's new web browser, <a href="http://www.google.com/chrome">Google Chrome</a>, that would have allowed an attacker to launch and run scripts on a compromised machine. The issue, originally discovered by Roi Saltzman of the IBM Rational Application Security Research Group, had been given a security rating of "high." Interestingly enough, although the attack takes advantage of security issues in Google Chrome, the initial entry point for the malicious code would have taken place in Internet Explorer. </p>

<p>Goolge has <a href="http://googlechromereleases.blogspot.com/2009/04/stable-update-security-fix.html">now released a patch</a> for this issue. If you want to make sure your browser is up-to-date, click through for the instructions.</p>]]>
      <![CDATA[

<h2>About the Security Issue(s) </h2>

<p>According to researcher, Roi Saltzman, a malicious attacker can use three separate issues in parts of Chrome to create attacks that endanger users who surf to a malicious web site using Internet Explorer. Chrome program manager, Mark Larson, explains that the flaw could have caused Google Chrome to "launch, open multiple tabs, and load scripts that run after navigating to a URL of the attacker's choice." (Yes, it seems that to get the malicious code working, a user would still need to be surfing with IE.)</p>

<h2>How to Fix Your Copy of Chrome</h2>

<p>Now that a patch is available, you can update <a href="http://www.google.com/chrome">Google Chrome</a> on your own. Even if you never run IE, it's always a good idea to have the latest version of Chrome installed. Although Google says that the browser will update itself automatically, on my machine, the update had not yet taken place on my ever-open copy of Chrome - I had to force the update manually. </p>

<p>If you want to do the same, you'll need to first click on the Settings menu in Chrome. This is the menu to the right of the address bar which is identified with an icon resembling a wrench. In that menu, click the option "About Google Chrome." If you need the update, it will begin automatically. Once complete, you'll be prompted to close and then reopen the browser for the update to finish installing. </p>

<p><img alt="about_google_chrome.png" src="http://www.readwriteweb.com/images/about_google_chrome.png"></p>

<p>To be extra sure that the update took, you can return to that menu option after relaunching Chrome and make sure that the version number reads <strong>1.0.154.59</strong>. </p>]]>
    </content>
  </entry>

  <entry>
    <id>tag:www.readwriteweb.com,2009://1.14806-comment:135712</id>
    <thr:in-reply-to ref="tag:www.readwriteweb.com,2009://1.14806" type="text/html" href="http://www.readwriteweb.com/archives/time_to_patch_google_chrome.php"/>
    <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/time_to_patch_google_chrome.php#c135712" />
    <title>Comment from Rameez Nooruddin on 2009-04-28</title>
    <author>
        <name>Rameez Nooruddin</name>
        <uri>http://friendfeed.com/remz</uri>
    </author>
    <content type="html" xml:lang="en" xml:base="http://friendfeed.com/remz">
        <![CDATA[<p>But the screenshot says 1.0.154.53 and also that Google Chrome has been updated.</p>

<p>So is it ...53 or ...59?</p>]]>
    </content>
    <published>2009-04-28T20:03:47Z</published>
  </entry>

  <entry>
    <id>tag:www.readwriteweb.com,2009://1.14806-comment:135582</id>
    <thr:in-reply-to ref="tag:www.readwriteweb.com,2009://1.14806" type="text/html" href="http://www.readwriteweb.com/archives/time_to_patch_google_chrome.php"/>
    <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/time_to_patch_google_chrome.php#c135582" />
    <title>Comment from www.manysoft.net on 2009-04-27</title>
    <author>
        <name>www.manysoft.net</name>
        <uri>http://www.manysoft.net</uri>
    </author>
    <content type="html" xml:lang="en" xml:base="http://www.manysoft.net">
        <![CDATA[<p>The best way to update is replace your Chrome with Firefox 3.0.9! </p>

<p>Chrome always "beta", so it is really necessary update...daily! I love Google but Chrome is exception!</p>]]>
    </content>
    <published>2009-04-28T00:42:15Z</published>
  </entry>

  <entry>
    <id>tag:www.readwriteweb.com,2009://1.14806-comment:135471</id>
    <thr:in-reply-to ref="tag:www.readwriteweb.com,2009://1.14806" type="text/html" href="http://www.readwriteweb.com/archives/time_to_patch_google_chrome.php"/>
    <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/time_to_patch_google_chrome.php#c135471" />
    <title>Comment from Emma on 2009-04-27</title>
    <author>
        <name>Emma</name>
        <uri></uri>
    </author>
    <content type="html" xml:lang="en" xml:base="">
        <![CDATA[<p>Does the newest version work OK on a Novel Netware machine. I've got install rights, but it would only stay on my machine for a single session. Google suggested I wasn't the only person with that issue! </p>]]>
    </content>
    <published>2009-04-27T15:43:52Z</published>
  </entry>

</feed>
