Connect with us

Hi, what are you looking for?

Major Financial PartnerMajor Financial Partner

Tech News

Researcher reveals ‘catastrophic’ security flaw in the Arc browser

Grayscale Arc logo on pink and black background
Illustration: Cath Virginia / The Verge

A security researcher revealed a “catastrophic” vulnerability in the Arc browser that would have allowed attackers to insert arbitrary code into other users’ browser sessions with little than an easily findable user ID. The vulnerability was patched on August 26th and disclosed today in a blog post by security researcher xyz3va, as well as a statement from The Browser Company. The company says that its logs indicate no users were affected by the flaw.

The exploit, CVE-2024-45489, relied on a misconfiguration in The Browser Company’s implementation of Firebase, a “database-as-a-backend service,” for storage of user info, including Arc Boosts, a feature that lets users customize the appearance of websites they visit.

In its statement,…

Continue reading…

You May Also Like

Business

After years of investing in self-checkout machines, some major retailers are starting to reverse course. Dollar General said it has eliminated self-checkout options at...

Editor's Pick

It was a very interesting week indeed. All-time high records continued to fall on a daily basis, but the complexion of the market most...

Editor's Pick

As a long-term stock trader, there’s one development in the stock market that takes me, and many others, to our collective knees. It’s a...

Editor's Pick

In this StockCharts TV video, Mary Ellen reviews where things stand after the markets close at another new high. She also shares what drove price...