Google fixes vulnerabilities in Chrome and adds malware detector

By Stuart Sumner

09 Feb 2012

Comment: 1

Google Chrome is currently a beta release for Windows XP and Windows Vista

Google has released an update for its Chrome browser that fixes 20 security flaws and adds a new feature to scan downloaded executable files for evidence of malware.

The new feature will make it safer for both enterprise users and consumers to download files from unfamiliar sources. Chrome will now check Google's own data on whether the hosting site is likely to serve malware.

Further reading

"In addition to checking a list of known bad files, Chrome also does checks on executable files (like ".exe" and ".msi" files)," wrote Noé Lutz, a Google software engineer on the firm's Chrome blog.

"If the executable doesn't match a whitelist, Chrome checks with Google for more information, such as whether the website you're accessing hosts a high number of malicious downloads."

While other browsers, including Mozilla's Firefox, warn users away from websites known to serve malware, actually scanning downloaded files is more commonly the job of a dedicated anti-virus (AV) product.

This is not the first time Google has encroached on territory normally reserved for AV vendors.

In July last year the firm said it would warn its users if it detected that they were infected with a particular strain of malware which it found by analysing unusual traffic patterns at one of its datacentres.

At the time, Graham Cluley, senior technology consultant at security firm Sophos, said that Google is not attempting to replace AV products, but complement them.

"Google has been filtering its search results for a number of years, and warning you if the results are malicious. They work with anti-virus vendors behind the scenes, and that's great for protecting end users."

Reader comments

Google and VirusTotal

It would be great if Google could check downloads automatically against VirusTotal. That's a much better solution than maintaining a single white list.

Unfortunately, I suspect the three dozen plus vendors who currently support VirusTotal might not want to continue this use of their signature files.

Bill

Posted by: Bill Pytlovany  11 Feb 2012

Have your say on this article

All fields required. Your email address will not be displayed on the site.

By submitting a comment you agree to abide by our Terms & Conditions

Technology Patent Wars

Large companies such as Microsoft, Facebook and Google have been hoovering up technology patents recently. Is this stifling innovation?

88 %

4 %

8 %