Google on Wednesday published exploit code for an unfixed vulnerability in its Chromium browser codebase that threatens millions of people using Chrome, Microsoft Edge, and virtually all other Chromium-based browsers.
The proof-of-concept code exploits the Browser Fetch programming interface, a standard that allows long videos and other large files to be downloaded in the background. An attacker can use the exploit to create a connection for monitoring some aspects of a user’s browser usage and as a proxy for viewing sites and launching denial-of-service attacks. Depending on the browser, the connections either reopen or remain open even after it or the device running it has rebooted.
Unfixed for 29 months (and counting)
The unfixed vulnerability can be exploited by any website a user visits. In effect, a compromise amounts to a limited backdoor that makes a device part of a limited botnet. The capabilities are limited to the same things a browser can do, such as visit malicious sites, provide anonymous proxy browsing by others, enable proxied DDoS attacks, and monitor user activity. Nonetheless, the exploit could allow an attacker to wrangle thousands, possibly millions, of devices into a network. Once a separate vulnerability becomes available, the attacker could use it to then compromise all those devices.Read full article
Comments
太空制药公司Varda Space Industries宣布与制药巨头United Therapeutics达成合作,将首次尝试在太空利用微重力环境生产药物。两家公司计划共同研究United的某些药物分子,看能否在太空形成地球上不存在的独特晶体结构,从而改善药物稳定性或特性。此前,太空制药主要依赖小型政府支持的实验项目进行探索,而Varda则通过利用SpaceX频繁又相对廉价的火箭发射机会,在降低成本的前提下进行这类实验。这项合作被视为太空药物商业化制造的重要里程碑,尽管实际应用仍处于早期阶段,但已引发包括美国军方的兴趣。