Connect with us

Hi, what are you looking for?

Tech News

Researcher reveals ‘catastrophic’ security flaw in the Arc browser

Illustration: Cath Virginia / The Verge

A security researcher revealed a “catastrophic” vulnerability in the Arc browser that would have allowed attackers to insert arbitrary code into other users’ browser sessions with little than an easily findable user ID. The vulnerability was patched on August 26th and disclosed today in a blog post by security researcher xyz3va, as well as a statement from The Browser Company. The company says that its logs indicate no users were affected by the flaw.

The exploit, CVE-2024-45489, relied on a misconfiguration in The Browser Company’s implementation of Firebase, a “database-as-a-backend service,” for storage of user info, including Arc Boosts, a feature that lets users customize the appearance of websites they visit.

In its statement,…

Continue reading…

You May Also Like

Editor's Pick

In this edition of StockCharts TV‘s The Final Bar, Dave shows how breadth conditions have evolved so far in August, highlights the renewed strength in the...

Tech News

Image: Becca Farsace / The Verge Instagram is a popular place to show off your latest photos, but if you’re a real photography enthusiast,...

Tech News

Rufino Choque, from the Urus Indigenous community, stands over a boat in the middle of the extinct Poopó Lake, which disappeared in 2015. |...

Politics

When word first broke that Joe Biden would be sitting down with Howard Stern for a live interview Friday on his SiriusXM show, it...

Generated by Feedzy