|
|
|
|
|
by ikeboy
3832 days ago
|
|
There's no indication that the bug was being actively exploited. Anyway, it's not clear what benefit was had over releasing the report but without the XSS link. Maybe even say "there's XSS on your site" but don't mention the exact link. Again, they should ban the extension completely if they think it's insecure, and if they haven't done that, they shouldn't be publicizing exploits. |
|
And it's been pointed out that they aren't able to remove the extension from users' machines due to how it bypasses the Chrome security system. So their best bet was to ask AVG to do the right thing. AVG won't or can't.
So, what can Google do? Just silently accept it? The 90-day policy is worthless in this case.