hooglle.blogg.se

Avast safe zone vs chrome
Avast safe zone vs chrome







  1. Avast safe zone vs chrome upgrade#
  2. Avast safe zone vs chrome code#

If you have SafeZone installed on your PC, you're doomed, since the malicious link can be opened in other browsers and work regardless. "This allows an attacker to read cookies, email, interact with online banking and so on." "Additionally, you can send arbitrary *authenticated* HTTP requests, and read the responses," Mr. Avast purposely disabled a Chromium security feature Ormandy noted, saying that bookmarks, preferences, passwords and cookies are automatically added to SafeZone without the user's consent.

avast safe zone vs chrome

"Although this attack relies on Avastium (Avast's port of Chromium), the victim does *not* have to be using it, and never has to have used it, because your profile is automatically imported from Chrome on startup," Mr.

Avast safe zone vs chrome code#

These commands could be bundled inside malicious JavaScript code that was executed locally on the user's computer, where localhost access would allow it to reach these open RPC endpoints, even if SafeZone was not actually running, and the malicious links were clicked inside another browser.Īn attacker wouldn't even need an info-stealing malware strain if they knew their target had Avast's SafeZone installed, a browser that was dumping everything out in the open. Users don't have to use the browser, only have it installedĪccording to the researcher's explanation, attackers could send malicious commands to an RPC endpoint that was left open in the browser's core engine. Ormandy explains, this poor excuse of a browser was allowing a third-party to carry out a series of attacks, all by fooling a user into clicking a link, which is not really that hard if you hide it under a short URL. Just like Chromodo, SafeZone is built on top of Chromium, the open source browser project on which Google Chrome, Vivaldi, and Opera are based as well.Īs Mr.

avast safe zone vs chrome

Avast safe zone vs chrome upgrade#

Antivirus makers should stick to antivirus softwareĬalled SafeZone and also known as Avastium, Avast's custom browser is offered as a bundled download for all those who purchase or upgrade to a paid version of Avast Antivirus 2016. While Chromodo was caught disabling a crucial security feature called Same Origin Policy (SOP), Avast's Chromium fork is much worse, bringing a series of problems, one of which allows attackers to list and read files from your computer after you click a simple malicious link. Just two days after Comodo's Chromodo browser was publicly shamed by Google Project Zero security researcher Tavis Ormandy, it's now Avast's turn to be scorned for failing to provide a "secure" browser for its users.









Avast safe zone vs chrome