Web Hack List

Collected research

Using Blended Browser Threats involving Chrome to steal files on your computer

CVE-2009-3931. Chrome auto-downloads files sent with Content-Disposition attachment and warns only on blacklisted extensions; .mht, .mhtml and .svg were absent from that list. Clicking the downloaded file opens it in IE6 or Safari from a local origin, where its script reads arbitrary local files. Google fixed it by extending the blacklist in v3.0.195.32.

Record

Researcher
Inferno
Published by
securethoughts.com
Topic
Browser

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Inferno, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .