Google Web Toolkit was first designed as a pack of utilities able to help users build their own AJAX applications. It seems like the purpose of the suite is a little different now when the
users might design unsafe web programs able to exploit the vulnerabilities discovered on certain websites. According to Dan Morrill, Google Developer Programs, some of the users that are looking to create malicious applications using the Google Web Toolkit suite managed to design tools based on malicious AJAX tricks able to exploit security flaws.
"Unfortunately, the same cool tricks that let you build AJAX sites and mashups also make it easy to build unsafe web applications. Some of the attacks evildoers have come up with are downright devious!
One of the key goals of GWT is to let developers focus on their users' needs, instead of on JavaScript and browser quirks. However, the consequences of a security exploit can be serious, so it's important that GWT developers understand how such attacks work, and how to prevent them," the Google employee sustained in the blog post.
This is not the first time when Google is involved in the security of our computers because the search giant is continuously fighting to improve the quality of the websites returned by the search engine. As you know, there are numerous malware notifications displayed straight on the SERP that are able to protect or at least, inform users about the presence of several infections on a certain page. At this time, Google works with StopBadware to flag the pages and malware and displays two types of notifications: one of them is placed just after the website link on the SERP while the other one is opened when the user clicks on the malicious page.