Chrome doesnt inform the user about failed update attemps
Reported by
mollyraz...@gmail.com,
Jul 30 2016
|
|
Issue descriptionVULNERABILITY DETAILS After your browser/computer gets hacked, the first thing an adversary/hacker does in order to keep persistence is crippling the browser's update process. Chrome does check updates, does it in the background, but never tells when an update failed. When Chrome cannot get information regarding updates it just keeps silent. This is problematic in so many levels. The user doesn't know when will a new update is coming, the user only gets a notice, when a new update is applied, but NEVER gets any indication that an update fetch failed... because ksfetch gets terminated or because some domains point to localhost or Little Snitch blocked some domains... and the list goes on. It would be much safer that whenever an update check or update fails for any reason, or after 2-3 consecutive failures the user would get a message balloon or some kind of icon indicating that the update is failing and the browser is not up to date, therefore cannot be considered "secure" anymore. The only place a user gets a notification about update problems are in the about/help section, but general users rarely if ever go there to update the browser themselves. VERSION Chrome Version: [52.0.2743.82] + [stable] Operating System: [OSX 10.11.6] REPRODUCTION CASE Cripple KSFETCH's net connection attempts via Little Snitch or any preferred way Use Chrome for a few weeks (do restarts too) and observe that no indication ever given to the user about failed update checks/updates.
,
Aug 1 2016
FWIW, the upgrade detector notifies users when Chrome is far out of date via the outdated upgrade bubble on Windows (and possibly all views-based desktop platforms). I'm not sure about the Mac. |
|
►
Sign in to add a comment |
|
Comment 1 by rickyz@chromium.org
, Jul 31 2016Labels: -Type-Bug-Security -Restrict-View-SecurityTeam Type-Feature
Status: Untriaged (was: Unconfirmed)
Summary: Chrome doesnt inform the user about failed update attemps (was: Security: Chrome doesnt inform the user about failed update attemps)