D
djbaxter
Guest
Flaw exposes Chrome, Firefox to clickjacking
By Liam Tung, ZDNet Australia
Jan 29, 2009
...more
By Liam Tung, ZDNet Australia
Jan 29, 2009
Security researchers have discovered a flaw affecting Google's Chrome browser that exposes it to clickjacking ? where an attacker hijacks a browser's functions by substituting a legitimate link with a link of the attacker's choice.
Google has acknowledged the flaw and is working towards a patch for Chrome versions 1.0.154.43 and earlier when running within Windows XP SP2 systems, according to SecNiche security researcher Aditya K Sood.
...
While Google is working on a fix, a spokesperson for the Australian arm of the company pointed out that clickjacking affected all browsers, not just Chrome.
"The [clickjacking] issue is tied to the way the web and web pages were designed to work, and there is no simple fix for any particular browser. We are working with other stakeholders to come up with a standardized long-term mitigation approach," they said.
However, chief executive of Australian security consultancy Novologica, Nishad Herath, told ZDNet.com.au that after running Sood's proof of concept he found that Internet Explorer 8 (release candidate 1 and beta 2 versions) and Opera 9.63 (the latest version) were not exposed to the flaw. But, like Chrome, Firefox 3.0.5 was exposed.
...more