Sunday, 23 February 2025
25.3 C
Singapore
36.8 C
Thailand
22.1 C
Indonesia
27.2 C
Philippines

Major browsers Safari, Chrome, and Firefox are fixing a critical security flaw

Discover how a critical security flaw affecting Safari, Chrome, and Firefox browsers is being fixed, protecting sensitive user data from cyberattacks.

A significant security flaw has been discovered in some of the world’s most popular web browsers, leaving them vulnerable to attacks that could compromise sensitive information. If you’re using Appleโ€™s Safari, Googleโ€™s Chrome, or Mozillaโ€™s Firefox, it’s crucial to be aware of this issue and the steps to address it.

A flaw that exposes your sensitive data

Cybersecurity experts from Oligo have revealed a vulnerability known as the “0.0.0.0-day attack,” which exploits how these major browsers handle queries to the 0.0.0.0 IP address. Under normal circumstances, this address redirects users to a different IP, often leading to โ€œlocalhost,โ€ which is typically a private server or computer. However, with this flaw, attackers can trick your browser into revealing private data by sending a malicious request to the 0.0.0.0 IP address.

The potential for harm is considerable, especially when the attack is executed through phishing or social engineering tactics. By persuading you to visit a malicious website, cybercriminals can access private data stored on your device. This is particularly concerning for those who manage web servers, as the attack surface is much more prominent in such cases.

Apple and Google rush to fix the flaw

This vulnerability is already being exploited in the wild, prompting developers to work on a solution. Apple and Google are both actively developing fixes for their browsers. Avi Lumelsky, an AI security researcher at Oligo, highlighted the potential risks, stating, โ€œDeveloper code and internal messaging are good examples of some of the information that can be accessed right away. But more importantly, exploiting 0.0.0.0-day can let the attacker access the internal private network of the victim, opening a wide range of attack vectors.โ€

The scope of the attack is limited, as it primarily affects individuals and businesses that host web servers. However, this still leaves many users exposed to potential breaches.

There is confirmed evidence that this flaw has been exploited in real-world scenarios. A Google security developer acknowledged the vulnerability in a post on the Chromium forum earlier this year. However, it’s important to note that this flaw can only be exploited on Apple devices. Microsoft has already taken steps to block the 0.0.0.0 IP address on Windows, and Apple plans to implement a similar measure in the upcoming macOS 15 Sequoia beta.

Meanwhile, Google is preparing to implement the fix on its Chromium and Chrome browsers. On the other hand, Mozilla is still exploring its options for addressing this issue in Firefox.

As these tech giants work to resolve the vulnerability, itโ€™s advisable to stay updated on the latest browser patches and updates. Ensuring that your browser is up-to-date is one of the best ways to protect yourself from potential cyber threats.

Hot this week

ASUS ZenScreen Duo OLED: A portable dual-screen setup for enhanced productivity

ASUS has launched the ZenScreen Duo OLED, a compact and lightweight dual-screen monitor designed for professionals and gamers on the go.

DJIโ€™s RS 4 Mini stabiliser now features advanced subject tracking

DJIโ€™s RS 4 Mini stabiliser introduces subject tracking, improved battery life, and better handling, making it an excellent tool for content creators.

Apple may introduce reverse wireless charging on iPhone 17 Pro

Apple may introduce reverse wireless charging in the iPhone 17 Pro, allowing users to power AirPods and Apple Watch without extra cables.

OPPO unveils Find N5: The worldโ€™s thinnest foldable phone with cutting-edge AI and battery life

OPPO launches Find N5, the world's thinnest foldable phone, featuring advanced AI, the largest inner screen, industry-best battery life, and powerful cameras.

Federal agency to deactivate charging stations and offload electric vehicles

The GSA is shutting down its EV chargers nationwide, calling them โ€œnot mission critical,โ€ and plans to offload newly purchased electric vehicles.

BT and Equinix expand partnership to enhance global interconnectivity

BT and Equinix expand their partnership to boost interconnectivity for multinational businesses, deploying BTโ€™s Global Fabric NaaS in 40+ Equinix data centres worldwide.

LG unveils new SKS branding for luxury kitchen suite at KBIS 2025

LG rebrands Signature Kitchen Suite to SKS at KBIS 2025, introducing new luxury appliances like a free-zone induction range and an advanced island system.

LG unveils advanced laundry solutions at KBIS 2025

LG unveils its latest heat pump washer and dryer lineup at KBIS 2025, featuring AI-driven efficiency, ventless design, and smart connectivity.

The Vision Pro is now easier to share, and getting a new iPhone app

Appleโ€™s Vision 2.4 update makes sharing the Vision Pro easier, introduces a new iPhone app for content discovery, and adds the Spatial Gallery app.

Related Articles