Share

Related Links

Related Stories

  • Adobe issues early quarterly security patches
    As promised earlier this month, Adobe has issued an advanced security update to sure up ‘critical’ vulnerabilities found with its Reader and Acrobat products.
  • Adobe fixes Flash flaw in five days
    Adobe has quietly fixed the 'critical' security flaw affecting its Flash and Reader software that it revealed earlier this week. The issue has been fixed in an urgent patch folded in with a raft of updates that are claimed to solve 32 documented problems with Adobe's software.
  • Applications under attack says Microsoft, Adobe
    Many in the security field agree that attack vectors have rapidly moved from exploiting operating system vulnerabilities to the application layer. Security specialists from Microsoft and Adobe lent their opinions as to why this is the case.
  • Google fixes Chrome flaws
    Google has closed four high-priority vulnerabilities in version 4 of its Chrome browser for Windows.
  • Google Chrome web browser gets more security features
    Google Chrome, the internet browser launched in late 2008, has been enhanced with a selection of new security features designed to make it harder for malware writers to infect client machines.

Top 5 Stories

News

Chrome browser to block outdated plug-ins

30 June 2010

Three researchers from the Google Security Team revealed that the Chrome web browser will attempt to enhance security through increased scrutiny of plug-ins, including blocking those that are out-of-date.

A recent blog posting on the Google Chromium Blog – co-authored by Chris Evans, Julien Tinnes, and Michal Zalewski – indicated that the open-source Chrome browser will block the use of outdated plug-ins at some point in the future.

The Google team said this was necessary because of the recent proliferation of attacks targeting plug-in exploits, including the rapid increase in attacks against Adobe plug-ins such as Reader and FlashPlayer.

No specific date for exactly when Chrome would roll out this feature was provided by the trio, only saying that it would be implemented in the “medium-term”. They did indicate, however, that Google Chrome would block the outdated plug-ins and aid users in updating them to the most current version.

A Google spokesperson told Infosecurity that there are no further details available on this new Chrome feature announced by the Security Team and declined to provide a timeline as to when it would go into effect.

The new policy comes the same week in which it was revealed that Google Chrome passed Apple’s Safari as the third most popular web browser in the US according to data from web analytics firm StatsCounter.

The group also said that Chrome would provide a warning for infrequently used plug-ins, which, in their opinion, “are widely installed but typically not required for today’s Internet experience”. The three security experts called these plug-ins “suspicious”, thus the need a user alert.

This article is featured in:
Application Security • Internet and Network Security

 

Comment on this article

You must be registered and logged in to leave a comment about this article.