Friday, September 5, 2008

Google Chrome Browser 0.2.149.27 (SaveAs) Remote BOF

We (SVRT-Bkis) have just discovered vulnerability in Google Chrome 0.2.149.27. This is a Critical Buffer Overflow Vulnerability permitting hacker to perform a remote attack and take complete control of the affected system.

We have submitted this Vulnerability to Google. They confirmed and assign a verifier for build 0.2.149.28.

Proof of Concept:
We tested Chrome 0.2.149.27 on Windows XP SP2 (Open Calculator)
http://security.bkis.vn/Proof-Of-Concept/PoC-XPSP2.html

With others Windows not XP SP 2:
http://security.bkis.vn/Proof-Of-Concept/PoC-Crash.html

- About Bkis :
Bkis (Bach Khoa Internetwork Security) is Vietnamese leading Center in researching, deploying network security software and solutions.

- Website : http://security.bkis.vn

No comments:

Post a Comment