Security researcher Aviv Raff has published a vulnerability affecting Google’s Toolbar browser feature. The weak spot Raff reported could let a hacker gain control of a user’s PC when the user tries to add a new Google Toolbar button. The vulnerability is based on spoofing a trusted site that would normally provide a safe toolbar button — basically tricking the user into downloading malicious files that could then be used, for example, to conduct nefarious activities like phishing attacks that could target banking information.
Security Specialist Spots Source Spoof Vulnerability in Google Toolbar
Posted by: Chris Maxcer December 19, 2007 11:57 AMSecurity researcher Aviv Raff has published a vulnerability affecting Google’s Toolbar browser feature. The weak spot Raff reported could let a hacker gain control of a user’s PC when the user tries to add a new Google Toolbar button. The vulnerability is based on spoofing a trusted site that would normally provide a safe toolbar button — basically tricking the user into downloading malicious files that could then be used, for example, to conduct nefarious activities like phishing attacks that could target banking information.