All the latest UK technology news, reviews and analysis

Critical vulnerability hits Google Desktop

by Tom Sanders in California

22 Feb 2007

Be the first to comment

  • Tweet this
Google Desktop
Google has released an update to patch a vulnerability in its Desktop application

Security researchers at Watchfire have uncovered a vulnerability in Google Desktop that could allow an attacker to steal confidential information and take control of a system. 

Google has released an update for the software to patch the vulnerability, which relies on cross-site scripting techniques.

An attacker could exploit the flaw through a specially crafted web link containing JavaScript code.

When a user clicks on the link, the code is executed by the Google Desktop application, which then allows the attacker to perform searches on the infected computer.

This could lead to exposed passwords, social security numbers or other confidential information.

The vulnerability is caused by the fact that Google Desktop is linked to the Google.com service.

Watchfire also warned that current antivirus software does not protect against such attacks.

Online application security is a hot topic in the security industry. Acunetix released a study last week in which it claimed that corporate websites contain an average of 66 security vulnerabilities in their online applications.  

Do you agree?

 

Add your comment

We won't publish your address
By submitting a comment you agree to abide by our Terms & Conditions. Your comment will be moderated before publication.

Poll

IT priorities for 2012

What is the most important IT priority for your company this year?

99%

0%

1%

0%

0%

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

Accurev

Top 5 software development challenges

This paper focuses on a series of best practices and techniques for development teams looking to improve their software development processes

Talend

Rubbish in, rubbish enterprise

Why good data management at all levels is essential in the modern business (video, 6mins)

Support Engineer - Cisco - LINUX - ISP - NOC - £30-40k

Support Engineer - Cisco - LINUX - ISP - NOC - £30-40k...

Netapp Storage Engineer - NCDA - NCIE - Unix/ Linux Skills

Netapp Storage Engineer - NCDA - NCIE - Unix/ Linux Skills...

Cisco ISP Pre-sales consultant - CCNA - CCNP - CCIE - £45-65k

Cisco ISP Pre-sales consultant - CCNA - CCNP - CCIE...

Netapp Storage Engineer - NCDA - NCIE - Unix/ Linux Skills

Netapp Storage Engineer - NCDA - NCIE - Unix/ Linux Skills...

To send to more than one email address, simply separate each address with a comma.