Collected research
Using Blended Browser Threats involving Chrome to steal files on your computer
CVE-2009-3931. Chrome auto-downloads files sent with Content-Disposition attachment and warns only on blacklisted extensions; .mht, .mhtml and .svg were absent from that list. Clicking the downloaded file opens it in IE6 or Safari from a local origin, where its script reads arbitrary local files. Google fixed it by extending the blacklist in v3.0.195.32.
Record
- Researcher
- Inferno
- Published by
- securethoughts.com
- Topic
- Browser
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Inferno, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .