Skip to main content

Potential Google Toolbar Hack

Potential Google Toolbar Hack

Are you like many others, with a Google Toolbar added on to your browser? If so, you’d better be careful about adding buttons to it. According to a story on TechNewsWorld, a security researcher has found a vulnerability that could allow a hacker to get control of your PC if you add a button.

Google has an API that allows users to create toolbar buttons, with the information stored in an XML file. A user needs to use a link to the XML file to install it.

Recommended Videos

The problem, researcher Aviv Raff found, occurs after someone clicks on that link, which is supposed to give information about the button. But an astute hacker can throw in a spoof redirected link instead, so instead of the button coming from Google, it comes from the hacker and could contain malware.

Of course, people generally don’t randomly add buttons to a toolbar, so any hacker would probably need to prompt a user into doing that, either by e-mail or using another site – quite a convoluted process.

"It is a good, effective way for attackers to gain their victim’s trust, but … there are other easier ways for attackers to gain access to their victim’s PC’s," Raff told TechNewsWorld. He added that he wasn’t surprised to find the vulnerability. "Even Google can have bugs. My recommendation for the end user is to avoid adding new buttons until Google provides a fixed version of the toolbar."

Affected are Google Toolbar 5 beta for Internet Explorer, Google Toolbar 4 for Internet Explorer, and Google Toolbar 4 for Firefox. However, the Firefox version only allows a partial spoof.

Digital Trends Staff
Digital Trends has a simple mission: to help readers easily understand how tech affects the way they live. We are your…
Google’s new Gemini 2.0 AI model is about to be everywhere
Gemini 2.0 logo

Less than a year after debuting Gemini 1.5, Google's DeepMind division was back Wednesday to reveal the AI's next-generation model, Gemini 2.0. The new model offers native image and audio output, and "will enable us to build new AI agents that bring us closer to our vision of a universal assistant," the company wrote in its announcement blog post.

As of Wednesday, Gemini 2.0 is available at all subscription tiers, including free. As Google's new flagship AI model, you can expect to see it begin powering AI features across the company's ecosystem in the coming months. As with OpenAI's o1 model, the initial release of Gemini 2.0 is not the company's full-fledged version, but rather a smaller, less capable "experimental preview" iteration that will be upgraded in Google Gemini in the coming months.

Read more
This cybersecurity disaster made Google’s top 10 searches of 2024
The blue screen of death in Windows.

Google recently released its Year in Search 2024, with a wide range of different topics reaching the top 10. Among major events like the Olympics and the U.S. presidential election is one name you may have forgotten about, but will remember for the chaos it caused. I'm talking, of course, about CrowdStrike, the cybersecurity firm founded in 2011 in Austin, Texas — the same one that was (at least partially) responsible for the largest IT outage ever.

So, what did CrowdStrike do exactly to earn its spot on the list? In a nutshell, it's responsible for the faulty code that meddled with core functions on the affected Windows computers. The error displayed messages on users' PCs saying: "Your PC ran into a problem and needs to restart." The result was downed PCs across the country, affecting a wide range of industries, but most notably, airports. From an IT perspective, this was a nightmare scenario.

Read more
Perplexity AI: how to use the ‘answer engine’ that’s taking on Google
Talking with Perplexity chatbot on Nothing Phone 2a.

Offering a unique take on web search, Perplexity has been a hit among its users (and a bane to its sources) since its debut last year. It's certainly become one of the most popular new AI tools to check out, perhaps second only to ChatGPT itself, which it's powered by.

Here's how the generative AI "answer engine" works and how to get started on using it.
What is Perplexity AI?
Perplexity AI Digital Trends

Read more