Google Fixes Dangerous Desktop Flaw | Internet News

Google Fixes Dangerous Desktop Flaw

Written By
Ed Sutherland
Ed Sutherland
Feb 21, 2007
2 minute read

For nearly a month, users of the Google Desktop application were exposed to a vulnerability that allowed remote hackers to snoop through private computer files.

The vulnerability was launched by malicious JavaScript code, enabling hackers to gain access to Office files, e-mails and chat logs.

Google  updated its desktop application with a patch that bars the execution of malicious scripts to protect users from future attacks. The search giant is asking users to download the latest version of Google Desktop.

“We have received no reports that this vulnerability was exploited,” Google spokesman Barry Schnitt told internetnews.com.

While the current dark clouds seem to have passed, the tight coupling between the desktop and Google.com has created “the perfect storm” for future security headaches, according to Danny Allen, security director for Waltham, Mass.-based Watchfire.

Watchfire discovered in January hackers could use a cross-site scripting attack to re-enable remote access to private files turned off by Google Desktop users. Users who clicked on a phishing e-mail or visited a malicious Web site would unknowingly trigger the script, Allen told internetnews.com.

Gartner research analyst John Pescatore told internetnews.com the vulnerability posed particular problems for businesses because software “can both expose desktop information to the broader Internet” and mix external information with internal sensitive data.

The Google Desktop flaw is just the latest security vulnerability the search company has had to deal with. In January, Google fixed a Gmail flaw that could have exposed e-mail users’ contact lists to attackers.

That security hole followed a scare over Google’s AdWords program that could have triggered cross-site scripting (XSS), defacement, hijacked pages or other attacks against Google Adwords advertisers.

Internet News Logo

InternetNews is a source of industry news and intelligence for IT professionals from all branches of the technology world. InternetNews focuses on helping professionals grow their knowledge base and authority in their field with the top news and trends in Software, IT Management, Networking & Communications, and Small Business.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.