Google Safe Browsing Incorrectly Blocking All Downloads From PortableApps.com (Workaround Done)

John T. Haller's picture
Submitted by John T. Haller on July 23, 2022 - 1:38am

Google Safe Browsing is currently blocking all downloads from PortableApps.com. The example file containing malware is GoogleChromePortable_103.0.5060.134_online.paf.exe which is verifiably not malware according to VirusTotal, another Google property. This file has false positive detections in Jiangmin, Antiy-AVL, and Malwarebytes. Antiy-AVL and Malwarebytes have been informed of their issue. Jiangmin has ignored previous false positive reports, but I have sent them an email anyway. A request for review with the details has been submitted but will take up to 72hrs according to Google. Third parties have stated that it generally takes longer.

Note that this will affect all browsers that make use of Google Safe Browsing including Firefox as well as services that use Google Safe Browsing as a feed like Microsoft Smart Screen within Microsoft Edge.

If anyone has an appropriate contact at Google, please reach out to us.

UPDATE (2022-07-23): We have switched open source app downloads (including the PA.c Platform) on the site to SourceForge while this issue persists. A workaround for freeware downloads is in progress.

UPDATE (2022-07-24): Antiy-AVL has fixed their false positive issue with Google Chrome Portable and the PortableApps.com Platform.

UPDATE (2022-07-24): Jiangmin responded that they will address the false positive. A workaround for freeware will require bringing another download server online as Google Safe Browsing is blocking all downloads from download2 regardless of link origin.

UPDATE (2022-07-25): ClamAV has fixed their false positive issue with the PortableApps.com Platform. Malwarebytes has sent an email requesting additional information for our open ticket. Firefox and Opera allow downloads from download2 without issue. Microsoft Edge shows an "isn't commonly downloaded" warning (Please click the menu and report the website as safe). Google Chrome is still broken.

UPDATE (2022-07-25): Spinning up a secondary download server VPS instance at a geographically separate data center.

UPDATE (2022-07-26): Jiangmin has fixed their false positive issue. Malwarebytes is in the process of whitelisting the reported packages.

UPDATE (2022-07-27): Linking to an alternate download server is blocked. Linking to a page on another domain that links to the download is also blocked. No word from Google after 5 days.

UPDATE (2022-07-27): Alternate download redirect appears to be working. Please test.

UPDATE (2022-07-28): Redirect fix implemented site-wide. Downloads should be working as normal. Still no response from Google.

UPDATE (2022-07-28): I've rebuilt the Google Chrome Portable and 64-bit installers as Repacked versions with no changes to the internal files. These are allowed through Google Safe Browsing.

Story Topic:

Comments

As the file is downloaded anyway, just rename the chrome temp file "Nicht bestätigt 885250.crdownload" (temp file name language depending) to "xxx.exe" and excute it.
Like I said, quick & dirty...

You can simply open the downloads tab (ctrl-j) and allow the download (if you are confident). While there is no button to allow the download in the status bar at the bottom, you find one in the downloads list.

Thanks for the hint! You're right, that's easier, "a little bit". Wink
As I used the keep option in the bottom line only (where it wasn't available anymore), I didn't expect, that I'm still having that option in the Downloads tab...

Besides: the download of PortableApps.com_Platform_Setup_22.0.1.paf.exe ("my issue") works w/o any objection with Chrome 103.0.5060.134 (64-bit) meanwhile, whereas specPortable_1.32.0.803_online.paf.exe and ZoomItPortable_6.0_English_online.paf.exe are still blocked.

John T. Haller's picture

ClamAV has fixed their false positive issue with the PortableApps.com Platform. Malwarebytes has sent an email requesting additional information for our open ticket. Firefox and Opera allow downloads from download2 without issue. Microsoft Edge shows an "isn't commonly downloaded" warning (Please click the menu and report the website as safe). Google Chrome is still broken.

Sometimes, the impossible can become possible, if you're awesome!

John T. Haller's picture

Spinning up a secondary download server VPS instance at a geographically separate data center.

Sometimes, the impossible can become possible, if you're awesome!

John T. Haller's picture

Linking to an alternate download server is blocked. Linking to a page on another domain that links to the download is also blocked. No word from Google after 5 days.

Sometimes, the impossible can become possible, if you're awesome!

John T. Haller's picture

An alternate download redirect appears to be working. It should be working for all logged in users now. You may need to clear your cache. Non-logged in users it should be about 15 minutes.

Please report if it's working for you.

Sometimes, the impossible can become possible, if you're awesome!