2 year old Unpatched Chrome bug, Tech Scammers are using

Ink

Administrator
Thread author
Verified
Staff Member
Well-known
Jan 8, 2011
22,361
Tech support scammers have started exploiting a two-year-old bug in Google Chrome to trick victims into believing their PC is infected with malware.

The bug was discovered in Chrome 35 in July 2014 in the history.pushState() HTML5 function, a way of adding web pages into the session history without actually loading the page in question.

The developer who reported the issue published code showing how to add so many items into Chrome’s history list that the browser would effectively freeze.

Continue Reading - Tech support scammers bite Chrome users with forgotten 2014 bug
 
W

Wave

Hmm, interesting, Google should focus on fixing this; they should have focused on a fix years ago IMO.

The developer who reported the issue published code showing how to add so many items into Chrome’s history list that the browser would effectively freeze.
In the background make a loop and recursively call the function; would result in the stack up for the history and eventually cause a crash (estimation of how the founder of the vulnerability did the freeze/crash).
 

Jake Miguel

Level 3
Verified
Well-known
Nov 14, 2016
134
There are various reasons that something can go wrong when Chrome tries to render a web page and the “Aw Snap!” is the catch-all error for those problems.

Typically these problems can be divided into two categories:

  1. Something wrong with the page data (e.g. the HTML, or cached HTML or proxied HTML) which is why reloading can sometimes solve the problem.
  2. Something wrong with the system (e.g. computer out of memory, problem with the Internet connection, Chrome executing in corrupted state) which is often fixed by rebooting.
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top