Alert! Big Data Breach, Data Over 2.5 billion Google Chrome Users’ At Risk – Check Here Full

Google Chrome is a web browser used by netizens from across the world. A latest cyber security firm claims to have detected a vulnerability in Google Chrome and Chromium-based browsers which puts data of over 2.5 billion users at risk.

News WhatsApp Group Links – Join Now

CONTENT TABLE

Join WhatsApp

Join WhatsApp

Now each and every piece of information is available on Google. Along with the growing acceptance, data threat risk is also growing. As we know that billions of users throughout the world use the well-known web browser Google Chrome. Dubbed CVE-2022-3656, this vulnerability allowed for the theft of sensitive files, such as crypto wallets and cloud provider credentials, the firm says in the post.

“The vulnerability was discovered through a review of the ways the browser interacts with the file system, specifically looking for common vulnerabilities related to the way browsers process symlinks,” the blog reads.

What is a symlink?

Imperva Red defines symlink or a symbolic link as a type of file that points to another file or directory. It allows the operating system to treat the linked file or directory as if it were at the symlink’s location. A symlink, it says can be useful for creating shortcuts, redirecting file paths, or organizing files in a more flexible way.

However, such links can also be used to introduce vulnerabilities if they are not handled properly.

In Google Chrome’s case, the issue arose from the way the browser interacted with symlinks when processing files and directories. To be specific, the browser did not properly check if the symlink was pointing to a location that was not intended to be accessible, which allowed for the theft of sensitive files, the blog post states.

How symlinks affected Google Chrome?

Explaining how the vulnerability impacted Google Chrome, the firm says that an attacker could create a fake website that offers a new crypto wallet service. The website, then could trick the user into creating a new wallet by requesting that they download their ‘recovery’ keys.

“These keys would actually be a zip file containing a symlink to a sensitive file or folder on the user’s computer, such as a cloud provider credential. When the user unzips and uploads the ‘recovery’ keys back to the website, the symlink would be processed and the attacker would gain access to the sensitive file,” the blog states.

What should Chrome users do?

Imperva Red says that it notified Google of the vulnerability and the issue was fully resolved in Chrome 108. It is advisable for users to always keep their software up to date in order to protect against such vulnerabilities.
.
PM Kisan 13th Installment Release Date: Beneficiary Status PDF 2023 Check By Mobile Number Here

News Categories

CLICK HERE TO: DOWNLOAD OUR MOBILE APPLICATION FOR LATEST UPDATES ON YOUR MOBILE PHONE
Kashmir News is now on Telegram. Click here to join our channel(@thekashmirnews) and stay updated with the latest news on Telegram
CLICK ON THE BELOW PROVIDED LINKS TO FOLLOW KASHMIR NEWS ON: 

OUR APPLICATION IS ALSO LIVE ON GOOGLE PLAY STORE, DOWNLOAD MOBILE APPLICATION

Indian Army Recruitment 2023 – Apply Online For Various (Men) & (Women) Vacancies | Salary Rs. 56100/- to 177500

You might also like