• Автор темы News
  • Дата начала
  • " /> News - Researcher reveals ‘catastrophic’ security flaw in the Arc browser | SoftoolStore.de - Софт,Avid Media Composer,Книги,Новости,News,Windows,Internet news. | бесплатные прокси (HTTP, Socks 4, Socks 5)

    News Researcher reveals ‘catastrophic’ security flaw in the Arc browser

    News

    Команда форума
    Редактор
    Регистрация
    17 Февраль 2018
    Сообщения
    22 702
    Лучшие ответы
    0
    Баллы
    2 093
    Offline
    #1

    Illustration: Cath Virginia / The Verge

    A security researcher revealed a “catastrophic” vulnerability in the Arc browser that would have allowed attackers to insert arbitrary code into other users’ browser sessions with little than an easily findable user ID. The vulnerability was patched on August 26th and disclosed today in a blog post by security researcher xyz3va, as well as a statement from The Browser Company. The company says that its logs indicate no users were affected by the flaw.

    The exploit, CVE-2024-45489, relied on a misconfiguration in The Browser Company’s implementation of Firebase, a “database-as-a-backend service,” for storage of user info, including Arc Boosts, a feature that lets users customize the appearance of websites they visit.

    In its statement,...

    Continue reading…
     
    Сверху Снизу