Skip to main content

Potential Google Toolbar Hack

Potential Google Toolbar Hack

Are you like many others, with a Google Toolbar added on to your browser? If so, you’d better be careful about adding buttons to it. According to a story on TechNewsWorld, a security researcher has found a vulnerability that could allow a hacker to get control of your PC if you add a button.

Google has an API that allows users to create toolbar buttons, with the information stored in an XML file. A user needs to use a link to the XML file to install it.

The problem, researcher Aviv Raff found, occurs after someone clicks on that link, which is supposed to give information about the button. But an astute hacker can throw in a spoof redirected link instead, so instead of the button coming from Google, it comes from the hacker and could contain malware.

Of course, people generally don’t randomly add buttons to a toolbar, so any hacker would probably need to prompt a user into doing that, either by e-mail or using another site – quite a convoluted process.

"It is a good, effective way for attackers to gain their victim’s trust, but … there are other easier ways for attackers to gain access to their victim’s PC’s," Raff told TechNewsWorld. He added that he wasn’t surprised to find the vulnerability. "Even Google can have bugs. My recommendation for the end user is to avoid adding new buttons until Google provides a fixed version of the toolbar."

Affected are Google Toolbar 5 beta for Internet Explorer, Google Toolbar 4 for Internet Explorer, and Google Toolbar 4 for Firefox. However, the Firefox version only allows a partial spoof.

Editors' Recommendations

Digital Trends Staff
Digital Trends has a simple mission: to help readers easily understand how tech affects the way they live. We are your…
Google’s Incognito Mode is in trouble
Google Chrome incognito mode screenshot

Google could soon be on the hook for deleting the private data of millions of users if the proposed settlement of a class action lawsuit is approved, according to The Verge.

The settlement proposal is part of the Brown v. Google lawsuit, for which the tech giant has agreed to “destroy or de-identify” the web browsing data it has saved from people utilizing the “Incognito Mode” feature on the Google Chrome browser. Google would be responsible for deleting billions of records and making sure undeletable records are not associated with individual users.

Read more
How to add audio or video to Google Slides
Grid view in Google Slides.

Google Slides is a great way to add style and flare to your everyday workplace presentations. It’s also a great tool for the classroom, that’s easy to adapt for students of all ages. Packed with graphics, animation tools, and other immersive features, Google Sheets even lets you upload your own audio and video to your slideshows.

Read more
How to convert Google Slides to PDF
Google Slides with a PDF image on a MacBook.

Google Slides is very convenient, but sometimes a PDF is more useful. Luckily, you can save a Google Slides deck as a PDF from both your computer or when you use the smartphone app. The format is more universal. You can easily print a PDF or even throw it into your custom GPT to have conversations based on the contents. The best part is that you can convert any Google Slides file into a PDF easily using these instructions.

Read more