GSMArena.com GSMArena.com

Tip us

883k

142k
87k
355k

RSS

Log in

Login with
Facebook Google

Sign up
  • Home
  • News
  • Reviews
  • FeaturedNew
  • Phone Finder
  • Tools
  • Glossary
  • Coverage
  • FAQ
  • Contact
HTC U11+ review
  • -
  • -
  • -

Serious new vulnerability found in Chrome for Android

  • Post your comment
  • Comments (28)

Ricky 14 November, 2015

Web browsers Android Google

A new vulnerability has been found (and thankfully, contained) by Qihoo 360 developer Guang Gong who had been working on the exploit for three months before demonstrating it at the PacSec conference in Tokyo.

The exploit worked by targeting the Chrome app’s JavaScript engine and installed a BMX bike game. Without requiring interaction of the user, the vulnerability demonstration exemplified complete control of the device. All the user has to do is visit a site that contains the vulnerability and the JavaScript hack will take care of the rest.

Google had a representative at this conference who was able to see the bug working in action. As reward for Gong’s work, he will be flown all the way to Vancouver for the CanSecWest Applied Security Conference where he will go on a ski trip.



Thankfully this vulnerability can be patched through a Chrome update through the Play Store, unlike Stagefright which required a software patch to the OS.

Most people are careful about the kinds of sites they visit. Particularly sites offering copyrighted material for free can be riddled with malware and virus links.

Source | Via

Related articles
  • Chrome will label all HTTP pages "Not secure" from July
  • Faster Firefox Quantum browser is now available
  • Google Chrome will soon allow permanent muting of websites
  • Chrome 60 for Android adds fast home screen search widget

Reader comments

  • Yani2000
  • 3pwD
  • 17 Nov 2015

... he will be flown all the way to Vancouver for the CanSecWest Applied Security Conference where he will go on a ski trip and have a little accident (and die). :P

  • Reply
C
  • Chuck Norris
  • 2Aui
  • 17 Nov 2015

Well i did not say all of the people that but iproduct for show... i said usually(mostly) people do this. and i mean a lot of them...

  • Reply
?
  • Anonymous
  • vx6d
  • 17 Nov 2015

what a nice gesture. You alert a big corp about a security risk and instead of denying everything to death and bringing in the lawyers, they reward the guy for finding and fixing their bad. thumbs up.

  • Reply
  • Read all comments
  • Post your comment
Total reader comments: 28

Phone finder

  • Samsung
  • Apple
  • Nokia
  • Sony
  • LG
  • HTC
  • Motorola
  • Huawei
  • Microsoft
  • Lenovo
  • Xiaomi
  • Google
  • Acer
  • Asus
  • Oppo
  • OnePlus
  • Meizu
  • BlackBerry
  • Alcatel
  • ZTE
  • Toshiba
  • Vodafone
  • Energizer
  • XOLO
  • Lava
  • Micromax
  • BLU
  • Gionee
  • vivo
  • LeEco
  • Panasonic
  • HP
  • YU
  • verykool
  • Maxwest
  • Plum

All brands Rumor mill

Top 10 by daily interest

  Device Daily hits  
1.Xiaomi Redmi Note 5 Pro68,703
2.Huawei P20 Pro51,299
3.Samsung Galaxy J7 Pro49,158
4.Xiaomi Black Shark44,037
5.Oppo F743,052
6.vivo V938,361
7.Xiaomi Redmi Note 5 (Redmi 5 Plus)35,044
8.Xiaomi Mi A131,835
9.Samsung Galaxy J7 Prime31,079
10.Samsung Galaxy S827,979

Top 10 by fans

  Device Favorites  
1.Samsung Galaxy Note81,623
2.Sony Xperia XZ Premium1,574
3.Nokia 81,271
4.Samsung Galaxy S8+1,204
5.Xiaomi Mi Mix1,076
6.LG G61,054
7.LG V30942
8.Xiaomi Mi A1896
9.Xiaomi Redmi Note 5 Pro856
10.Xiaomi Mi 6831

Home News Reviews Compare Coverage Glossary FAQ RSS feed Facebook Twitter

© 2000-2018 GSMArena.com Mobile version Contact us Advertising Privacy Terms of use

CDN by