Dynamics of Google, Apple and Microsoft when the browser has a security error
While Apple and Google urgently sought to patch security holes in Safari (CVE-2017-2419) and Chrome (CVE-2017-5033) browsers, Microsoft did not notice. This security vulnerability was discovered by Cisco Talos researchers in Safari, Chrome, and Edge browsers, but Microsoft believes that this security is due to design.
According to researcher Nicolai Grødum at Cisco Talos, this vulnerability is classified as a exit from CSP (Content Security Policy) - a mechanism that allows web developers to configure HTTP headers and instruct users to access Source browser (JavaScript, CSS). Content security policy (CSP) is one of the tools that browsers use to implement SOP - Same-Origin Policy within the browser.
Grødum said he found out how an attacker who bypassed CSP, downloaded malicious JavaScript code on a remote site and performed intrusion operations such as collecting information from the user's cookie or recording the syntax press key in page structure, .
Exploiting vulnerabilities is quite simple
Exploiting this vulnerability in the browser is quite simple - at least for those with a background in web development. An attacker just needs to open a new website via the '_blank' method and use the document.write function to write malicious code inside this page before downloading the actual content. Malicious content (also known as initial XSS attack code) remains and helps attackers overcome CSP protection.
Grødum found the vulnerability in November last year. This issue is ranked seriousness CVSS is 4.3 / 10.
Users of the Edge browser are easily vulnerable to this vulnerability while Google Chrome users 57.0.2987.98, iOS 10.3, and Safari 10.1 or newer are all protected. And Firefox is lucky to be unaffected.
You should read it
- Vulnerabilities discovered in many web browsers that allow users to be tracked through installed applications
- Find security holes on every site with Nikto
- Protect your Web browser
- The unsafe 'feature' on UC Browser allows hackers to take control of Android phones remotely
- IBM developed a new technology to patch security holes
- Microsoft introduced a tool to fix security holes in IE 9 and 10
- 5 common errors in managing security vulnerabilities
- HP publishes a series of critical vulnerabilities in the Teradici PCoIP protocol
May be interested
- Google launched Chrome 33, patched 7 new security bugsin preparation for the annual pwnium and pwn2own hack contest scheduled to take place today march 13, google released chrome 33 on tuesday and patched a total of 7 security holes for chrome's browser. me
- Detecting a serious error on Firefox browser may damage the operating systema security researcher and software engineer named sabri haddouche discovered a serious bug in the firefox browser that could damage the system, freezing microsoft edge, safari, and internet explorer.
- Fix the abrupt Flash Player error on Google Chromegoogle chrome is the default browser for many users because it is easy to use and has many features. however, there are some errors on google chrome that users cannot find a way to fix. one of the problems is that the flash player is suddenly stopped for unknown reasons. this happens when you are playing a video that requires shockwave flash player.
- Revealing new features of Chrome browserthe browser development race is taking place among 'heavyweights' rivals such as mozilla, google and microsoft, as companies compete to launch superior features for this product. recently, google has added a series of competitive features to the chrome browser.
- Google Chrome supports Window XP until 2015microsoft will stop support for windows xp in 6 months, but google still extends support for chrome browser on this aging operating system to at least april 2015 - a year after microsoft stopped patching for xp
- Google surpassed Microsoft in browser market sharedue to the small market share of windows phone on mobile land and the strong rise of chrome on all platforms, microsoft has lost the no. 1 position in browser market share in the us.
- Tor browser is available on Google Playafter 8 months of testing, finally the famous security web browser tor was officially available on the google play store.
- Chrome OS: Google goes deep into Microsoft territorywith the browser-based chrome os (chrome os), google is increasing challenges with rival microsoft.
- How to fix RESULT_CODE_HUNG error in Google Chromeis chrome stopping your browser due to the result_code_hung error? google's browser can experience this problem due to poor internet connection, outdated chrome version or full cache, among many other reasons.
- Google promises to give priority to quickly fix Chrome's battery drain errorafter being told by forbes magazine about the problem of costing the laptop battery of chrome browser, google made a formal announcement and promised to fix the bug in upcoming versions.