Chrome Zero-Day Exploited to Harvest User Data via PDF Files

Discussion in 'malware problems & news' started by itman, Feb 27, 2019.

  1. itman

    itman Registered Member

    Joined:
    Jun 22, 2010
    Posts:
    8,594
    Location:
    U.S.A.
    https://www.securityweek.com/chrome-zero-day-exploited-harvest-user-data-pdf-files
     
  2. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    17,606
    Location:
    The Netherlands
    That's why I never use PDF viewers that are integrated into the browser, in the past there have been numerous of vulnerabilities in both Chrome and Firefox.
     
  3. Beyonder

    Beyonder Registered Member

    Joined:
    Aug 26, 2011
    Posts:
    545
    Sounds pretty harmless though. Expected a lot worse.
     
  4. shmu26

    shmu26 Registered Member

    Joined:
    Jul 9, 2015
    Posts:
    1,550
    Right. It could be used as a spy tool to prepare a targeted attack against a high-value target, but that is about it.
     
  5. itman

    itman Registered Member

    Joined:
    Jun 22, 2010
    Posts:
    8,594
    Location:
    U.S.A.
    When malware "recon" activity like this is detected, it is usually a prelude to an imminent malware attack using the vulnerability. Hence the pen-testers public release so people can be warned and take appropriate precautions.
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.