First Bug for Google Chrome- crashes with DoS

Submitted by vinny on Thu, 09/04/2008 - 03:24.

You thought Google made a bug free Google Chrome? Google actually claimed that Chrome won't crash in any condition especially when one tab crashes, since it allocates memory seperately to each tab and when one crashes only that memory is released but the rest is intact so every tab acts like a new browser instant.


However, Rishi Narang from Evil Fingers is typing and releasing a proof of concept for a denial of service vulnerability that is successfully crashing the Chrome browser with all tabs.


Narang Quotes,


“An issue exists in how chrome behaves with undefined-handlers in chrome.dll version 0.2.149.27. A crash can result without user interaction. When a user is made to visit a malicious link, which has an undefined handler followed by a ’special’ character, the chrome crashes with a Google Chrome message window “Whoa! Google Chrome has crashed. Restart now?”. It crashes on “int 3″ at 0×01002FF3 as an exception/trap, followed by “POP EBP” instruction when pointed out by the EIP register at 0×01002FF4.”


I am not really blaming Google for this coz I believe every product in Beta stage has some bugs and this is one of them. I am confident Google will fix this within a week or even less.


However my first experience with Google Chrome is fantastic, It's atleast 100X faster than stupid IE and 20X faster than FF and 10X faster than my beloved OPERA.


 


 


Post new comment

  • Web page addresses and e-mail addresses turn into links automatically.
  • Lines and paragraphs break automatically.
  • Links to specified hosts will have a rel="nofollow" added to them.

More information about formatting options