Saturday, 23 November 2024
30.8 C
Singapore

Major browsers Safari, Chrome, and Firefox are fixing a critical security flaw

Discover how a critical security flaw affecting Safari, Chrome, and Firefox browsers is being fixed, protecting sensitive user data from cyberattacks.

A significant security flaw has been discovered in some of the world’s most popular web browsers, leaving them vulnerable to attacks that could compromise sensitive information. If you’re using Apple’s Safari, Google’s Chrome, or Mozilla’s Firefox, it’s crucial to be aware of this issue and the steps to address it.

A flaw that exposes your sensitive data

Cybersecurity experts from Oligo have revealed a vulnerability known as the “0.0.0.0-day attack,” which exploits how these major browsers handle queries to the 0.0.0.0 IP address. Under normal circumstances, this address redirects users to a different IP, often leading to “localhost,” which is typically a private server or computer. However, with this flaw, attackers can trick your browser into revealing private data by sending a malicious request to the 0.0.0.0 IP address.

The potential for harm is considerable, especially when the attack is executed through phishing or social engineering tactics. By persuading you to visit a malicious , cybercriminals can access private data stored on your device. This is particularly concerning for those who manage web servers, as the attack surface is much more prominent in such cases.

Apple and Google rush to fix the flaw

This vulnerability is already being exploited in the wild, prompting developers to work on a solution. Apple and Google are both actively developing fixes for their browsers. Avi Lumelsky, an AI security researcher at Oligo, highlighted the potential risks, stating, “Developer code and internal messaging are good examples of some of the information that can be accessed right away. But more importantly, exploiting 0.0.0.0-day can let the attacker access the internal private network of the victim, opening a wide range of attack vectors.”

The scope of the attack is limited, as it primarily affects individuals and businesses that host web servers. However, this still leaves many users exposed to potential breaches.

There is confirmed evidence that this flaw has been exploited in real-world scenarios. A Google security developer acknowledged the vulnerability in a post on the Chromium forum earlier this year. However, it’s important to note that this flaw can only be exploited on Apple devices. has already taken steps to block the 0.0.0.0 IP address on Windows, and Apple plans to implement a similar measure in the upcoming macOS 15 Sequoia beta.

Meanwhile, Google is preparing to implement the fix on its Chromium and Chrome browsers. On the other hand, Mozilla is still exploring its options for addressing this issue in Firefox.

As these tech giants work to resolve the vulnerability, it’s advisable to stay updated on the latest browser patches and updates. Ensuring that your browser is up-to-date is one of the best ways to protect yourself from potential cyber threats.

Hot this week

Cybersecurity unicorn Semperis strengthens identity-driven resilience in Singapore after major funding success

Semperis enhances cybersecurity in Singapore with US$125M funding, partnerships, and training to combat growing cyber threats and ransomware attacks.

Apple may have upgraded M4 MacBook Pro with quantum dot display technology

Apple may have added quantum dot technology to the M4 MacBook Pro display, enhancing its colour accuracy and performance while staying eco-friendly.

Anglo-Chinese School students win top prize in Samsung Solve for Tomorrow 2024

Anglo-Chinese School students win Samsung Solve for Tomorrow 2024 with innovative smart glasses for the hearing impaired. Other projects celebrated.

Xi promotes a ‘shared future in cyberspace’ at internet forum amid rising US-China tech tensions

Xi Jinping called for global collaboration in cyberspace at the World Internet Conference as US-China tensions grow over AI and tech decoupling.

Splunk launches advanced observability and security solutions for Microsoft Azure customers

Splunk and Microsoft launch native solutions on Azure, enhancing digital transformation with AI-powered observability and security tools.

Google reportedly cancels Pixel Tablet 2 and exits tablet market again

Google cancels the Pixel Tablet 2, signalling another exit from the tablet market. Poor sales and competition from Apple may be to blame.

Apple’s Find My will let you share lost item locations with airlines

Apple’s Find My app in iOS 18.2 lets you share lost item locations, helping airlines recover luggage with privacy-focused temporary links.

Anglo-Chinese School students win top prize in Samsung Solve for Tomorrow 2024

Anglo-Chinese School students win Samsung Solve for Tomorrow 2024 with innovative smart glasses for the hearing impaired. Other projects celebrated.

DXC Technology and ServiceNow partner to accelerate generative AI adoption for businesses

DXC Technology partners with ServiceNow to fast-track generative AI adoption through a new Centre of Excellence, combining industry expertise and AI solutions.

Related Articles

Popular Categories