Imperva uncovers Google Chrome vulnerability | #firefox | #chrome | #microsoftedge

Imperva has discovered a Google Chrome vulnerability that could potentially allow malicious actors to hack into users’ computers to find sensitive information from Facebook and other personal platforms.

The bug researchers unearthed use the Blink engine in Google Chrome to break into the browser. Although the vulnerability has apparently been fixed with the latest update to Google Chrome, 58% of Chrome users haven’t updated their browsers, leaving them exposed to the vulnerability.

“Attackers could establish the exact age or gender of a person, as it is saved on Facebook, regardless of their privacy settings,” said Ron Masas, a researcher at security firm Imperva. “With several scripts running at once each testing a different and unique restriction the bad actor can relatively quickly mine a good amount of private data about the user.”

Imperva explained the security hole takes advantage of Audio/Video HTML tags to generate requests to a target resource. It watches the actions made to the resource and then poses questions to the browser about its user based upon the pages it’s accessed, requiring yes or no answers.

So if someone visits the site (such as Facebook), hidden video or audio tags will be implemented into the browser. It will then request Facebook posts the attacker has planted and can then analyse the victim’s personal data including information such as their age as it’s saved on Facebook.

“For example, a bad actor can create sizeable Facebook posts for each possible age, using the Audience Restriction option, making Facebook reflect the user age through the response size,” Masas said. “The same method can be used to extract the user gender, likes, and many other user properties we were able to reflect through crafted posts or Facebook’s Graph Search endpoints.”

Google patched the security hole in Chrome 68’s release after being advised about the potential problem by Imperva’s researchers.

Featured Resources

Accelerate your business with hybrid cloud

Tap into benefits of both cloud and on-premise

Free Download

Unified endpoint management solutions 2021-22

Analysing the UEM landscape

Free Download

The Total Economic Impact™ of IBM Spectrum Virtualize

Cost savings and business benefits enabled by storage built with IBM
Spectrum Virtualize

Free download

The COO’s pocket guide to enterprise-wide intelligent automation

Automating more cross-enterprise and expert work for a better value stream for customers

Free Download



Original Source by [author_name]

Leave a Reply

Your email address will not be published.

26 + = thirty five