Wednesday, 24 December 2025
28.3 C
Singapore
24.2 C
Thailand
22.6 C
Indonesia
27.1 C
Philippines

Major browsers Safari, Chrome, and Firefox are fixing a critical security flaw

[output_post_excerpt]

A significant security flaw has been discovered in some of the world’s most popular web browsers, leaving them vulnerable to attacks that could compromise sensitive information. If you’re using Apple’s Safari, Google’s Chrome, or Mozilla’s Firefox, it’s crucial to be aware of this issue and the steps to address it.

A flaw that exposes your sensitive data

Cybersecurity experts from Oligo have revealed a vulnerability known as the “0.0.0.0-day attack,” which exploits how these major browsers handle queries to the 0.0.0.0 IP address. Under normal circumstances, this address redirects users to a different IP, often leading to “localhost,” which is typically a private server or computer. However, with this flaw, attackers can trick your browser into revealing private data by sending a malicious request to the 0.0.0.0 IP address.

The potential for harm is considerable, especially when the attack is executed through phishing or social engineering tactics. By persuading you to visit a malicious website, cybercriminals can access private data stored on your device. This is particularly concerning for those who manage web servers, as the attack surface is much more prominent in such cases.

Apple and Google rush to fix the flaw

This vulnerability is already being exploited in the wild, prompting developers to work on a solution. Apple and Google are both actively developing fixes for their browsers. Avi Lumelsky, an AI security researcher at Oligo, highlighted the potential risks, stating, “Developer code and internal messaging are good examples of some of the information that can be accessed right away. But more importantly, exploiting 0.0.0.0-day can let the attacker access the internal private network of the victim, opening a wide range of attack vectors.”

The scope of the attack is limited, as it primarily affects individuals and businesses that host web servers. However, this still leaves many users exposed to potential breaches.

There is confirmed evidence that this flaw has been exploited in real-world scenarios. A Google security developer acknowledged the vulnerability in a post on the Chromium forum earlier this year. However, it’s important to note that this flaw can only be exploited on Apple devices. Microsoft has already taken steps to block the 0.0.0.0 IP address on Windows, and Apple plans to implement a similar measure in the upcoming macOS 15 Sequoia beta.

Meanwhile, Google is preparing to implement the fix on its Chromium and Chrome browsers. On the other hand, Mozilla is still exploring its options for addressing this issue in Firefox.

As these tech giants work to resolve the vulnerability, it’s advisable to stay updated on the latest browser patches and updates. Ensuring that your browser is up-to-date is one of the best ways to protect yourself from potential cyber threats.

Hot this week

Thoughtworks: Singapore’s financial OS upgrade, agentic AI and the race for the future of wealth

How agentic AI could reshape wealth management in Singapore by enhancing personalisation, improving responsiveness and elevating the role of advisers.

OPPO announces global winners of the 2025 Photography Awards

OPPO names global winners of its 2025 Photography Awards, recognising mobile photography that captures culture, emotion, and everyday life worldwide.

The Oscars to stream exclusively on YouTube in 2029

The Oscars will stream exclusively on YouTube from 2029, signalling a major shift in how the iconic awards reach global audiences.

Damon and Baby offer a devilishly entertaining retro shooter experience

Damon and Baby is a retro-inspired twin-stick shooter that blends fast action, exploration, and quirky co-op gameplay.

Indie Game Awards withdraws Clair Obscur honours over generative AI use

Indie Game Awards withdraws Clair Obscur’s top honours after confirming generative AI assets were used during the game’s production.

Square Enix releases Final Fantasy VII Remake Intergrade demo on Switch 2 and Xbox

Free demo for Final Fantasy VII Remake Intergrade launches on Switch 2 and Xbox, letting players carry progress into the full 2026 release.

AI designs a Linux computer with 843 parts in a single week

Quilter reveals a Linux computer designed by AI in one week, hinting at a future where hardware development is faster and more accessible.

Super Mario Bros inspired Hideo Kojima’s path into game development

Hideo Kojima reveals how Super Mario Bros convinced him that video games could one day surpass movies and led him into game development.

Indie Game Awards withdraws Clair Obscur honours over generative AI use

Indie Game Awards withdraws Clair Obscur’s top honours after confirming generative AI assets were used during the game’s production.

Related Articles

Popular Categories