Google has fixed a security flaw in its desktop search software that created a means for hackers to rifle through personal files on users’ PCs.
A failure in Google Desktop to “properly encode output containing malicious or unexpected characters” created a means for hackers to cross from the web environment to the desktop application environment.
So if you are running Google Desktop we suggest you update it ASAP.
Google released an updated version of Google Desktop that fixes the local cross-site scripting flaw earlier this month, but many users may not have gotten the patch, said Danny Allan, director of security research for Watchfire. Because of the popularity of Google Desktop, there could be a large number of users with vulnerable systems.
Recent in Exploits/Vulnerabilities:
- Andrew Auernheimer AKA Weev Gets 41 Months Jail Time For GET Requests
- Evernote Hacked – ALL Users Required To Reset Passwords
- Apple, Facebook & Hundreds More Hacked By 0-Day Java Exploit
- Google Desktop 3 Enterprise
- Google Desktop Privacy? OR Lack Of..
- Google Releases New Browser Chrome – Vulnerabilities on First Day
Most Read in Exploits/Vulnerabilities:
- Learn to use Metasploit – Tutorials, Docs & Videos - 219,214 views
- AJAX: Is your application secure enough? - 117,887 views
- eEye Launches 0-Day Exploit Tracker - 84,883 views