Chrome vulnerability could have led to widespread data theft | Computer Weekly
Summary
Researchers at Imperva have revealed their hand in uncovering and fixing a potentially dangerous vulnerability in Google’s Chrome and Chromium-based browsers that, left untreated, could have enabled threat actors to steal sensitive files from more than 2.5 billion worldwide users of the web browsing technology. “In the case of the vulnerability we disclosed to Google, the issue arose from the way the browser interacted with symlinks when processing files and directories,” explained Masas in his write-up. This issue is commonly known as symbolic link following.” In one potential attack scenario exploiting CVE-2022-3656, an attacker could create a fake website to offer a crypto wallet service, tricking the user into creating a new wallet by downloading supposed recovery keys in the form of zip file, which in fact contained a symlink to a sensitive file or folder on the user’s computer, such as a cloud service credential. In such a scenario, the victim may not even notice they had been tricked, since a great many crypto wallets or other online services require their users to download recovery keys to serve as backups should they lose access to their account, perhaps because they had forgotten their password. Users may also wish to consider using a hardware wallet to store crypto assets, and improving the security of their credentials with password managers or multifactor authentication (MFA).