A serious vulnerability in the Chrome browser puts the data of 2.5 billion users at risk

 
 
 

The Google Chrome browser and other browsers based on the Chromium project have been found to have serious security vulnerabilities, affecting about 2.5 billion users worldwide.

Researchers at Imperva said that the vulnerability is serious because it allows hackers to steal sensitive files such as cryptocurrency wallet contents and login credentials, reports Al-Rai daily.

The researchers discovered a flaw in the way Chrome and Chromium-based browsers (the open source web browser project) handle symbolic links.

Researchers explain that "Symlinks" are files that point to other files or directories in operating systems, and allow these files or directories to be treated as if they were in the same location as the original files.

"These (symbolic links) can be useful for creating shortcuts, redirecting file paths, or organizing files in a more flexible manner," according to the researchers. But if these files are not handled properly, they can become a vulnerability for hackers.

Researchers described a possible attack scenario in which a hacker creates a fake cryptocurrency wallet and website asking users to download its recovery keys.

If the user downloads these files, they may contain symbolic links to sensitive files on the user's computer, and the browser's failure to handle these files may result in the theft of cryptocurrency wallets and credentials.

The worst part, according to the researchers, is that the victim will be completely unaware that their sensitive data has been compromised, especially since many cryptocurrency wallets and other online services require users to download recovery keys to access their accounts.

The attacker would exploit this common practice by sending the user a zip file containing a symbolic link, instead of the actual recovery keys, according to the researchers.

The security vulnerability is currently being tracked and addressed by Google with version 108 of the Chrome browser.

Prior to downloading any recovery keys, users should install the latest version of the browser and browsers based on the Chromium project.

 
****************************************************