Vulnerability in Chrome's AVG Web TuneUp

The AVG Web TuneUp Chrome extension added to browsers with the of AVG antivirus, contained a critical bug that allowed attackers to obtain user browsing history, cookies, and more.AVG Web TuneUp Chrome

Η ευπάθεια ανακαλύφθηκε από τον ερευνητή ασφαλείας του Google Zero, Tavis Ormandy, who has been working with AVG for the past two weeks to fix the problem.

As Mr Ormandy said in his error report, the AVG Web TuneUp extension, which lists over nine χρήστες στη σελίδα του Chrome Web Store, ήταν ευάλωτη σε XSS ( ) attacks.

Attackers who knew this security vulnerability were able to access user's cookies, browsing history, and various other details exposed through Chrome.

During his investigation, Mr Ormandy discovered that many of the custom JavaScript APIs added to Chrome by the extension are responsible for the error, allowing attackers to access personal information.

The new 4.2.5.169 version of AVG TuneUp Web resolves the issue. Meanwhile, Google blocks AVG from in-line installations of this extension. This means that users who want to install it should have it search the Chrome Web Store.

iGuRu.gr The Best Technology Site in Greecefgns

every publication, directly to your inbox

Join the 2.087 registrants.

Written by Dimitris

Dimitris hates on Mondays .....

Leave a reply

Your email address is not published. Required fields are mentioned with *

Your message will not be published if:
1. Contains insulting, defamatory, racist, offensive or inappropriate comments.
2. Causes harm to minors.
3. It interferes with the privacy and individual and social rights of other users.
4. Advertises products or services or websites.
5. Contains personal information (address, phone, etc.).