• $
  • £

Developer finds Chrome eavesdropping bug

Developer finds Chrome eavesdropping bug
25.01.2014 19:14
Any computer running the Chrome browser can be subverted to eavesdrop on conversations happening around it, claims a developer.

Israeli coder Tal Ater found the bug while working on his own speech recognition software.Despite Google finding a way to fix the bug in October 2013 the update has yet to be rolled out to Chrome, he said.Google said there was no immediate threat to users from the speech recognition system.Listening in"Even while not using your computer - conversations, meetings and phone calls next to your computer may be recorded and compromised," wrote Ater in a blogpost explaining what he had found.The bug emerges when malicious sites try to subvert the way Chrome handles speech recognition, he said.Typically, people must manually grant permission to each site that wants to access a computer's microphone to listen in. Once permission has been granted Chrome lets people know a site is listening via a blinking red dot on the tab for that site.In a video accompanying the blogpost, Ater showed how a malicious attacker could use specially crafted code to exploit these permissions to launch a "pop-under" window that starts the speech recognition system."The malicious site you visited can continue listening in on you long after you have left it," said Ater. "As long as Chrome is still running nothing said next to your computer is private."Google was told about the bug in September last year, said Ater and soon after found a way to fix it. However, this has yet to be included in updates for Chrome.Ater asked why Chrome remains vulnerable and was told that Google was still waiting for the World Wide Web consortium (W3C), which defines how the web develops, to make a decision about what to do."The security of our users is a top priority, and this feature was designed with security and privacy in mind," said a Google spokesperson. "We've re-investigated and still believe there is no immediate threat, since a user must first enable speech recognition for each site that requests it.""The feature is in compliance with the current W3C specification, and we continue to work on improvements," he added told tech news site The Register.(BBC)ANN.Az

Similar news
Similar news
China sent 280 container trains to Europe via Middle Corridor since early 2024
Business 16:09
China sent 280 container trains to Europe via Middle Corridor since early 2024
Azerbaijan and Ukraine explore avenues for deepening economic ties
Business 17:30
Azerbaijan and Ukraine explore avenues for deepening economic ties
Azerbaijan imports $900M worth of goods from Türkiye in 5 months
Business 13:30
Azerbaijan imports $900M worth of goods from Türkiye in 5 months
35 projects implemented in liberated territories of Azerbaijan in 2023
Business 16:00
35 projects implemented in liberated territories of Azerbaijan in 2023
Israeli companies invited to investment projects in Karabakh’s industrial parks
Business 18:30
Israeli companies invited to investment projects in Karabakh’s industrial parks
Italian firms interested in participating in projects to be implemented in Karabakh
Business 14:00
Italian firms interested in participating in projects to be implemented in Karabakh
Azerbaijani economy minister, governor of St. Petersburg mull enhancing joint activities in shipbuilding
Business 15:00
Azerbaijani economy minister, governor of St. Petersburg mull enhancing joint activities in shipbuilding
Russia-Azerbaijan trade reaches $4.4 billion, Russian ambassador says
Business 10:00
Russia-Azerbaijan trade reaches $4.4 billion, Russian ambassador says
Azerbaijan to increase value of non-oil exports to $5B by 2026
Business 14:00
Azerbaijan to increase value of non-oil exports to $5B by 2026
Anews TV

Our official Youtube channel

Subscribe