Table of Contents
Learn about google tested the top 5 Browsers, safari results with the most, who may be affected, and which practical steps users or administrators can take to reduce exposure.
Google Tested the Top 5 Browsers, Safari Results with the Most Security Flaws Overview
The Project Zero team in Google has just created a browser engine DOM testing tool and tested the top 5 browsers today. The results show that Apple's Safari browser has a lot of errors.
The tool called Domato is a security toolkit, using random data and analyzing the output to find anomalies. Google's engineer Ivan Fratric created Domato with the goal of detecting the DOM engine's error, a browser element used to read HTML and arrange in the DOM (Document Object Model), then display within the browser Users still see on the screen.
Google: Errors on the DOM Engine Need to Be Prioritized
Fratric said he focused on the DOM engine because 'rarely did anyone release security updates that didn't contain at least some errors on the DOM engine'. Although Flash errors appear in many browsers, when Flash goes away (by 2020), the attacker will focus on the DOM engine. For Domato, he hopes to help check and patch security issues related to the DOM engine before it's too late.
Discover 17 Security Bugs in Safari's DOM Engine
To demonstrate, Fratric performed tests on five popular browsers Chrome, Firefox, Internet Explorer, Edge and Safari, bringing in 100 million fuzz tests.
The results show that Safari has the most errors with 17 bugs. Behind with Edge with 6 bugs, IE and Firefox have 4 bugs and Chrome only has 2 errors. Not counting errors that are not confidential.
Fratric also pointed out that if Microsoft does not add MemGC (preventing UAF security holes) on IE and Edge, their results will be much worse.
* Total is 33 but there are 2 errors affecting many browsers. ** One of the errors found in Firefox is on the Skia graphics library, not in Firefox's source code. But code errors are contributed by Mozilla engineers to Skia.
Google said it had informed the parties about new errors discovered and included a copy of Domato to enable them to check further. Fratric also puts Domato source code on GitHub https://github. com/google/domato and hopes others will use it to work on other applications, not just the browser DOM engine. Domato is also not the only tool of Google to detect security flaws, before it also had OSS Fuzz and syzkaller.
Security note: Threat conditions and vendor guidance can change. Install current updates and verify any advisory with the official vendor before taking action.
FAQ
Why does google Tested the Top 5 Browsers, Safari Results with the Most Security Flaws matter?
Learn about google tested the top 5 Browsers, safari results with the most, who may be affected, and which practical steps users or administrators can take to reduce exposure.
Who may be affected by this issue?
The impact depends on the affected product, version, account, device, or network. Review the article details and the vendor's current advisory to confirm whether your environment is exposed.
How can users reduce the risk?
Install current security updates, use official downloads, enable strong account protection, maintain tested backups, and follow the latest guidance from the relevant vendor.
Reader Comments 0
Sign in with email or Google to join the discussion.