Google Chrome plays outside of Vista Security Zones

It seems Chrome is not located in Program Files. There are some major implications with this!

I posted last night about some things regarding Chrome: Google Chrome the good and the petty. I point out that unfortunately searches in the address bar are severely weighted. A fact which perhaps does not mean all that but it is a sad fact that the giants can't keep the competitive game above the edge of the sand box.

One thing immediately got commented by my friend and colleague Håkan Reis. I thought he'd comment more on the UX bits I posted since he's very focused on that area. But he put another issue at the top of the list. I concur that this actually warrants a post of it's own!

Google Chrome installs under your local user settings. In my case its the folder C:\Users\Magnus\AppData\Local\Google\Chrome\Application. This means we now have an app running outside of Vistas regular security zones.

You need elevated rights in Vista to modify files that lie under C:\Program Files but not to modify files under C:\Users\<your user>\. This means that any app that might run on your machine can do what ever changes to the Chrome application that it wishes!

This ensues a major security issue for Chrome! Or did I miss something in Security 101?

Cheers,

/Magnus

Technorati Tags: ,

posted @ Friday, September 05, 2008 9:03 AM

Print

Comments on this entry:

# Google Chrome - critical security issues

Left by It's all about looks at 9/5/2008 11:18 AM
Gravatar

# Google Chrome may need more work to be fully secure under Vista

Left by Harry Waldron - My IT Forums Blog at 9/5/2008 4:09 PM
Gravatar
A visitor to my blog, shared this interesting comment. While my personal experience has been limited

# Google Chrome may need more work to be fully secure under Vista

Left by Harry Waldron - Microsoft MVP Blog at 9/5/2008 4:16 PM
Gravatar
A visitor to my blog, shared some interesting findings related to Vista. While my personal experience

# Google Chrome may need more work to be fully secure under Vista

Left by Harry Waldron - My IT Forums Blog at 9/5/2008 4:17 PM
Gravatar
A visitor to my blog, shared some interesting findings related to Vista. While my personal experience

# Google Chrome may need more work to be fully secure under Vista

Left by Harry Waldron - Microsoft MVP Blog at 9/5/2008 4:31 PM
Gravatar
A visitor to my blog, shared some interesting findings related to Vista. While my personal experience

# Google Chrome may need more work to be fully secure under Vista

Left by Harry Waldron - Microsoft MVP Blog at 9/5/2008 4:33 PM
Gravatar
A visitor to my blog, shared some interesting findings related to Vista. While my personal experience

# Google Chrome may need more work to be fully secure under Vista

Left by Harry Waldron - My IT Forums Blog at 9/5/2008 4:33 PM
Gravatar
A visitor to my blog, shared some interesting findings related to Vista. While my personal experience

# Google Chrome may need more work to be fully secure under Vista

Left by myITforum.com at 9/5/2008 4:40 PM
Gravatar
A visitor to my blog, shared some interesting findings related to Vista. While my personal experience

# re: Google Chrome plays outside of Vista Security Zones

Left by Rod Trent at 9/5/2008 6:16 PM
Gravatar
Oh, and uninstalling leaves the Google updater behind in the same unprotected directory structure:

myitforum.com/.../...-uninstall-leaves-behind.aspx

# More goodness…Chrome installs outside of the Vista protected zone

Left by Rod Trent at myITforum.com at 9/5/2008 6:18 PM
Gravatar
Google Chrome plays outside of Vista Security Zones

# More goodness…Chrome installs outside of the Vista protected zone

Left by myITforum.com at 9/5/2008 7:06 PM
Gravatar
Google Chrome plays outside of Vista Security Zones

# Google Chrome - critical security issues

Left by It's all about looks at 9/6/2008 4:23 PM
Gravatar

# re: Google Chrome plays outside of Vista Security Zones

Left by Mayern Ridd at 9/7/2008 12:33 PM
Gravatar
also you can download 10 more google chrome theme in http://www.freechromethemes.com

# 

Left by blog.reis.se at 11/29/2008 10:11 PM
Gravatar
Google Chrome - critical security issues

Your comment:



 (will not be displayed)


 
 
 
Please add 8 and 5 and type the answer here:
 

Live Comment Preview:

 
Magnus Mårtensson
Senior Consultant .com
Contact