Forum Thread: Google Chrome not safe

You are currently viewing a forum thread in the Secunia Community Forum. Please note that opinions expressed here are not of Secunia but solely reflect those of the user who wrote it.

This thread was submitted in the following forum:
PSI

This thread has been marked as locked.
butter Google Chrome not safe
Member 28th Dec, 2015 23:39
Ranking: 17
Posts: 10
User Since: 10th Aug, 2009
System Score: N/A
Location: US
Secunia Advisory SA67608 says google chrome 47.0.2526.106 not safe for browsing and you should remove or disable (can't do that) Can anyone tell me if google chrome will be updating soon and is it safe just not to use it until it is updated. Don't know what to do.

Maurice Joyce RE: Google Chrome not safe
Handling Contributor 29th Dec, 2015 10:33
Score: 12325
Posts: 9,575
User Since: 4th Jan 2009
System Score: N/A
Location: UK
This is the link to the Flexera Secunia advisory you refer to:

https://secunia.com/advisories/67608/

I cannot see any reference to version 47.0.2526.106. The advisory indicates that any version PRIOR to 47.0.2526.73 is vulnerable and you should update to 47.0.2526.73

This missive from Google indicates that version 47.0.2526.73 is the latest stable version and is secure.

http://googlechromereleases.blogspot.ca/2015/12/st...

Can you publish the hyperlinks where Flexera Secunia refer to version 47.0.2526.106 and advise users remove or disable this version?

--
Maurice

Microsoft Surface 4 Intel i7 64Bit
Windows 10 Pro version 1809 Build 17763.404
16 GB RAM
IE & Edge Only
Was this reply relevant?
+0
-0
Anthony Wells RE: Google Chrome not safe
Expert Contributor 29th Dec, 2015 14:18
Score: 2542
Posts: 3,402
User Since: 19th Dec 2007
System Score: N/A
Location: N/A

Hello ,

The Chrome Blogspot pages can be difficult to navigate (like this website) but the latest display of all the Chrome channels is here :-

http://googlechromereleases.blogspot.fr/


and the latest release is 47.0.2526.106 and is installed on my system and PSI marks it as "Up to Date" :ie: secure .

It sjould be noted that as of now Google have not updted the embedded PPAPI Flash plug-in which remains as .228 and is insecure . Either the individual plug-in or the entire browser will be updated . In the interim the plug-in can be disabled via "settings" if so desired .

The PSI version 2.x continues to show the latest version(106) to be "not safe for browsing in the "Secure Browsing" module because of SA67608 .

So it is still unclear !!

Anthony



--


It always seems impossible until its done.
Nelson Mandela
Was this reply relevant?
+0
-0
butter RE: Google Chrome not safe
Member 29th Dec, 2015 15:39
Score: 17
Posts: 10
User Since: 10th Aug 2009
System Score: N/A
Location: US
Thank everyone. I am using PSI version 2 which shows my google chrome is still not safe to use but at least I know it is OK. The adobe flash is also up to date.
Was this reply relevant?
+0
-0
Anthony Wells RE: Google Chrome not safe
Expert Contributor 29th Dec, 2015 16:10
Score: 2542
Posts: 3,402
User Since: 19th Dec 2007
System Score: N/A
Location: N/A

Hello again ,

Your PSI 2.x "scan results" module should show your Chrome .106 as up to date , but it does not necessarily have the PPAPI Flash plug-in updated from .228 to .267 . This is because it is an embedded file and so is NOT tracked by the PSI but it is still a security risk .

Your "Secure Browsing" module shows Chrome .106 as being "insecure" due to a "possibly" outdated SA - difficult to say but more likely a False positive .
The Adobe Flash being displayed for Chrome is an NPAPI plug-in NO LONGER used by Chrome and is not relevant . It is being tracked if you have Flash installed in Firefox or Safari , etc. It should say NPAPI in the display entry which you can double click to see the location . In itself it does not make Chrome secure whilst the PPAPI is not updated .

Hope that is clearer .

Anthony

--


It always seems impossible until its done.
Nelson Mandela
Was this reply relevant?
+0
-0

This thread has been marked as locked.