SHARE
Follow this article on Twitter Facebook LinkedIn Bookmark and Share
Home >> Security

Google first to patch Flash bug with Chrome update

Google first to patch Flash bug with Chrome update

By:  Gregg Keizer  On: 17 Mar 2011 For: ComputerWorld (US) Creator
 

Takes advantage of deal with Adobe to push zero-day fix a week before others get protection. Adobe said it would patch Flash Player for Windows, Mac OS X and Linux sometime next week, but did not put a date on the calendar

Google Inc. on Tuesday updated Chrome, patching a flaw in the browser's copy of Flash Player.

The move let Chrome beat rival browsers to the punch: Users of Internet Explorer (IE), Firefox, Safari and Opera won't receive a Flash update from Adobe until next week.

On Monday, Adobe announced that attackers are exploiting an unpatched, or "zero-day," vulnerability in Flash Player using malicious Microsoft Excel documents attached to e-mail messages. Adobe said it would patch Flash Player for Windows, Mac OS X and Linux sometime next week, but did not put a date on the calendar.

Yesterday, Google pushed a Chrome update to users running the stable and beta builds of the browser.

"This release contains an updated version of the Adobe Flash player," Jason Kersey, a Chrome program manager, said in a Tuesday post to a Google blog.

After updating Chrome to version 10.0.648.134, the browser reports that it's running Flash Player 10.2.154.25, a step up from the 10.2.154.18 bundled with the last update of the browser.

Adobe confirmed today that Chrome's integrated copy of Flash includes the patch for the zero-day vulnerability.

"As part of our collaboration with Google, Google receives updated builds of Flash Player for integration and testing," said Adobe spokeswoman Wiebke Lipps today. "Once testing is completed for Google Chrome, the release is pushed via the Chrome auto-update mechanism."

Adobe is still testing the patched Flash Player across its full list of supported platforms, which range from Windows and Mac OS X to Linux and Android, Lipps said.

Google has been including fixes for Flash Player in its Chrome updates since April 2010 . Chrome is the only browser to automatically update Flash Player with its own patch mechanism.

Chrome users have gotten the jump on others before when it comes to Flash fixes. Last September, for example, Google updated the browser, and delivered a patched Flash Player,three days before Adobe .

Chrome 10.0.648.134 with the patched Flash Player can be downloaded can be downloaded for Windows, Mac OS X and Linux from Google's Web site. Users already running the browser will be updated automatically.

Sign up for our Newsletters
Tags: flash, Chrome, Google

 












Print |  Views: 2639   |   Rating:offoffoffoffoff  (0 votes)
Rate this article on a scale of
1 to 5 stars,5 being the best.




gregg keizer Gregg Keizer is a contributor to the International Data Group (IDG) News Service, which publishes global technology stories from bureaus around the world to more than 300 publications in more than 60 countries.

Recent Canadian IT Jobs




Related Content

Google ships beta of Chrome for Mac
Google ships beta of Chrome for MacA year after releasing the PC version, the search giant offers for download Mac and Linux versions of its browser, but with significant missing features
Google upgrades Chrome dev tools
Google upgrades Chrome dev toolsImprovements include the addition of a heap profiler for JavaScript and a tab offering overviews of where time is spent when loading a Web app
Adobe promises patch for critical Flash, Reader flaw
Adobe promises patch for critical Flash, Reader flawAdobe knew about the vulnerability since December but never got around to fix it
VIDEO: Google exec clarifies Chrome questions
highlights from google’s mobile engineering manager alex nicolaou’s keynote speech on chrome and the chromium.org open source project at ibm’s cascon 2008 conference in richmond hill, ontario. (video runs approx. 5 minutes)
blog comments powered by Disqus