Skip to main content

Potential Google Toolbar Hack

Potential Google Toolbar Hack

Are you like many others, with a Google Toolbar added on to your browser? If so, you’d better be careful about adding buttons to it. According to a story on TechNewsWorld, a security researcher has found a vulnerability that could allow a hacker to get control of your PC if you add a button.

Google has an API that allows users to create toolbar buttons, with the information stored in an XML file. A user needs to use a link to the XML file to install it.

The problem, researcher Aviv Raff found, occurs after someone clicks on that link, which is supposed to give information about the button. But an astute hacker can throw in a spoof redirected link instead, so instead of the button coming from Google, it comes from the hacker and could contain malware.

Of course, people generally don’t randomly add buttons to a toolbar, so any hacker would probably need to prompt a user into doing that, either by e-mail or using another site – quite a convoluted process.

"It is a good, effective way for attackers to gain their victim’s trust, but … there are other easier ways for attackers to gain access to their victim’s PC’s," Raff told TechNewsWorld. He added that he wasn’t surprised to find the vulnerability. "Even Google can have bugs. My recommendation for the end user is to avoid adding new buttons until Google provides a fixed version of the toolbar."

Affected are Google Toolbar 5 beta for Internet Explorer, Google Toolbar 4 for Internet Explorer, and Google Toolbar 4 for Firefox. However, the Firefox version only allows a partial spoof.

Editors' Recommendations

Digital Trends Staff
Digital Trends has a simple mission: to help readers easily understand how tech affects the way they live. We are your…
How to delete Google Chrome on Windows and Mac
Google Chrome with pinned tabs on a MacBook on a table.

Google Chrome is a user-friendly web browser that is packed with useful features and intuitive controls. It’s also the default browser for pretty much any Chrome-branded product you purchase. Even if you prefer Safari or Firefox, we bet Chrome has one or two things you would dig. But what if you've added Google Chrome to your Windows or macOS machine, and you’ve decided you don’t like the dang thing?

Read more
Google Drive vs. Dropbox: which is best in 2024?
Google Drive in Chrome on a MacBook.

Google Drive and Dropbox are two of the most popular cloud storage providers, if not some of the best. They offer a range of exciting features, from secure file storage and transfer, to free storage, file syncing, extensions, chat-app integration, and more. But while they might go toe to toe on some cloud storage specifications, there are others where one is the clear winner. The question is, which one is the best in 2024?

Let's take a close look at Google Drive and Dropbox to see how their latest head to head turns out.
Google Drive wins the free storage battle
Both Dropbox and Google Drive offer free storage space for those who would like to try out their respective services before putting down a few dollars a month for something more expansive and permanent. Google Drive comes standard, with 15GB of free space, far more than Dropbox's initial free storage offering of just 2GB.

Read more
Google’s AI just got ears
Gemini Advanced home page.

AI chatbots are already capable of "seeing" the world through images and video. But now, Google has announced audio-to-speech functionalities as part of its latest update to Gemini Pro. In Gemini 1.5 Pro, the chatbot can now "hear" audio files uploaded into its system and then extract the text information.

The company has made this LLM version available as a public preview on its Vertex AI development platform. This will allow more enterprise-focused users to experiment with the feature and expand its base after a more private rollout in February when the model was first announced. This was originally offered only to a limited group of developers and enterprise customers.

Read more