Google issues patch for desktop vulnerability

COMMENT ON THIS ARTICLE

Security researchers have discovered a serious flaw in Google Inc.’s desktop software that could be used to wreak havoc on a victim’s computer.

The bug, which was made public Wednesday by Watchfire Corp., has now been fixed. While Google is automatically delivering a patch, Google Desktop users who want to be sure they are running the latest version of the software can download it here. Users should be running version 5.0.701.30540 or later, said Google Spokesman Barry Schnitt, via e-mail.

Google was first notified of the problem on Jan. 4, and produced its fix on Feb. 1, a Watchfire spokesman said Wednesday.

In addition to its bug fix, Google has added, “another layer of security checks to the latest version of Google Desktop to protect users from similar vulnerabilities in the future,” Schnitt said. “We have received no reports that this vulnerability was exploited,” he added.

Watchfire’s research underscores the danger of integrating Web-based applications with the desktop, the company said in a white paper, published Wednesday.

The flaw lies in a search parameter used by Google Desktop’s Advanced Search feature, which could be used to execute malicious JavaScript code, according to Watchfire.

For this attack to work, the criminal would have to first go through a number of steps, including hacking Google.com to find a cross site scripting vulnerability on the Web site — something that has been done several times in the past year, according to Watchfire.

If successful, however, the attack would be devastating. A criminal could search for anything on the computer or even take over the victim’s computer by tricking Google desktop into running malicious software stored on another computer, Watchfire claims.

COMMENT ON THIS ARTICLE

Would you recommend this article?

Share

Thanks for taking the time to let us know what you think of this article!
We'd love to hear your opinion about this or any other story you read in our publication.


Jim Love, Chief Content Officer, IT World Canada

Featured Download

Featured Articles

Cybersecurity in 2024: Priorities and challenges for Canadian organizations 

By Derek Manky As predictions for 2024 point to the continued expansion...

Survey shows generative AI is a top priority for Canadian corporate leaders.

Leaders are devoting significant budget to generative AI for 2024 Canadian corporate...

Related Tech News

Tech Jobs

Our experienced team of journalists and bloggers bring you engaging in-depth interviews, videos and content targeted to IT professionals and line-of-business executives.

Tech Companies Hiring Right Now