Providing Free and Editor Tested Software Downloads
< HOME | TUTORIALS | GEEK-CADE| WEB TOOLS | YOUTUBE | NEWSLETTER | DEALS! | FORUMS | >

MajorGeeks.com - The Few, The Proud, The Geeks.

Software Categories

All In One Tweaks
Android
Antivirus & Malware
Appearance
Back Up
Browsers
CD\DVD\Blu-Ray
Covert Ops
Drivers
Drives (SSD, HDD, USB)
Games
Graphics & Photos
Internet Tools
Linux Distros
MajorGeeks Windows Tweaks
Multimedia
Networking
Office & Productivity
System Tools

Other news

· How To and Tutorials
· Life Hacks and Reviews
· Way Off Base
· MajorGeeks Deals
· News
· Off Base
· Reviews




spread the word

· YouTube
· Facebook
· Instagram
· Twitter
· Pintrest
· RSS/XML Feeds
· News Blur
· Yahoo
· Symbaloo

about

· Top Freeware Picks
· Malware Removal
· Geektionary
· Useful Links
· About Us
· Copyright
· Privacy
· Terms of Service
· How to Uninstall

top downloads

1. GS Auto Clicker
2. Macrium Reflect FREE Edition
3. Smart Defrag
4. Visual C++ Redistributable Runtimes AIO Repack
5. Visual C++ Runtime Installer (All-In-One)
6. McAfee Removal Tool (MCPR)
7. MusicBee
8. Rufus
9. K-Lite Mega Codec Pack
10. Sergei Strelec's WinPE
More >>

top reads

Star How to Disable 1-Click Ordering on Amazon (and Avoid Surprise Charges)

Star How to Fix Shallow Paint Layer Depth in Bambu Studio

Star Aviator Betting Game Secrets: Unlock 97% RTP & Triple Your Wins

Star Windows Recall: What It Is, Why Hackers Will Love It, and How to Stay Safe

Star Star Trek Fleet Command Promo Codes: Redeem Codes for Free Shards, Blueprints And Resources

Star How To Use VLC Media Player to Trim Video Clips

Star What Is the $WinREAgent Folder and Can I Delete It?

Star Swear Your Way to Better Search Results

Star How to Get a Dark Start Menu and Taskbar in Windows 10 & 11

Star Enable, Disable, Manage, Delete or Create a System Restore Point


MajorGeeks.Com » News » October 2013 » Google Chrome vulnerability leaves sensitive data at risk

Google Chrome vulnerability leaves sensitive data at risk


Posted by: Jon Ben-Mayor on 10/11/2013 08:30 AM [ comments Comments ]


Identity Finder has exposed a potentially serious flaw on Google Chrome; the flaw is in Chrome's caching mechanism and allows sensitive data to be stored unencrypted directly onto your hard drive, this is happening without your knowledge or consent.




Identity Finder researchers performed in-depth scans on several employee computers using the latest version of Sensitive Data Manager (SDM). During the scan, SDM pinpointed several Chrome SQLite and protocol buffers storing a range of information including names, email addresses, mailing addresses, phone numbers, bank account numbers, social security numbers and credit card numbers. SDM found similar data among all employees who consistently use Chrome as their primary browser.

They confirmed with each employee that sensitive data, such as social security and bank account numbers, were only entered on secure, reputable websites. Despite employees having entered this information on secure websites, Chrome saved copies of this data in the History Provider Cache. Other SQLite databases of interest include “Web Data” and “History.” On Windows machines, these files are located at %localappdata%GoogleChromeUser DataDefault.

Chrome browser data is unprotected, and can be read by anyone with physical access to the hard drive, access to the file system, or simple malware. There are dozens of well-known exploits to access payload data and locally stored files. To see whether Chrome data was at risk of theft, Identity Finder researchers created a small proof-of-concept exploit that would upload Chrome cache data to a third party site (See screenshot below). In this attack scenario, an attacker would only have to trick a user into permitting access to their file system. Attackers could acquire vast amounts of personal information without requiring users to enter anyting into a form, or system credentials.

CyberTruth contacted Google spokeswoman Leslie Miller for comment; Miller says she's looking into it.

"By default Google Chrome stores (web) form data, including data entered on secure websites, to automatically suggest for later use," says Feinman. "This stored data is unencrypted text and accessible if your computer or hard drive is stolen or is infected with malware."

The risks of identity theft to consumers are obvious. Businesses that must comply with the payment card industry's PCI-DSS security rules could fail audits if employees are in the practice of entering credit card data in Chrome.

An extra step employees and consumers can take is to regularly clear Chrome's cache. Until Google addresses this gaping security hole, Chrome users would be wise to learn how to clear Chrome's cache, and do it often.

Security researchers have long warned Google of the dangers presented by poorly-conceived security and privacy controls. "This is no longer a theoretical risk that can be dismissed," Feinman says. "The fact that these security risks have been hard-coded into Chrome for so long only adds to the urgency for browser makers to secure all stored browser data."


« Pigg faces shoplifting charges for stealing sex toy (Mugshot) · Google Chrome vulnerability leaves sensitive data at risk · iPhone 5C sales estimates chopped by analyst »




Comments
comments powered by Disqus

MajorGeeks.Com » News » October 2013 » Google Chrome vulnerability leaves sensitive data at risk

© 2000-2025 MajorGeeks.com
Powered by Contentteller® Business Edition