Feeds

Big browser builders scramble to fix cross-platform zero-day flaw

Mac users, you're just as vulnerable to phishing scheme

Choosing a cloud hosting partner with confidence

Browser manufacturers will release an update in the next few weeks to block a new type of malware that exploits a cross-platform flaw that allows attackers access to Mac, PC, mobile, and even games console internet users.

"PC, Android, Mac – the vulnerability hits them all the same," said Sveta Miladinov, founder of the British-based security research firm MRG Effitas, at a Kaspersky Lab meeting in San Francisco on Thursday. "It is being exploited in the wild, but not at a high rate at the moment. I can't say any more until the patches are finished, but it's a true cross-platform browser vulnerability."

Miladinov's team had seen the sample working against one particular browser type and has taken a sample in the wild. By reverse-engineering it, the team showed that the code can be used to get around the security of most of the major browsers. His company then got in contact with manufacturers to get the flaw fixed before going public with the news.

This is the kind of exploit browser makers loath and security experts have come to fear, and it appears that the malware is primarily intended for use in phishing attacks rather than giving access to full systems. More details will be made available once the zero-day flaw patch is released, but even that may not be enough to provide protection.

"For many users, even old attacks are zero-day for them personally, because too few people actually update their systems, especially Mac users," Peter Stelzhammer, cofounder of security researchers AV-Comparitives told The Register.

"It's very difficult to get malware to take control of a fully patched Mac computer, but what's the point? The main problem is phishing and that's browser-based," Stelzhammer said. "It doesn't really matter if it's a PC, Mac, or games console; you're still vulnerable to browser attack."

Browser security

Safari isn't the worst browser out there, but not by much (click to enlarge)

He pointed to recent research from his company that showed that while Safari isn't the most vulnerable browser out there, it's far from the best either. The AV-Comparitives test found that for phishing attacks, Safari stopped just 16 per cent of test malware, slightly ahead of Firefox but well behind Chrome and Internet Explorer.

The going price for a really extensive zero-day for operating systems could be as high as $200,000 on the vulnerability market, according to Tiffany Rad, analyst at Kaspersky Lab's global research & analysis team, and browser cracks are also valuable. But malware writers looking to economize are taking a cheaper option to crack systems.

"If you're a writer, it's a lot easier and cheaper to pack in a few hundred not-quite zero-day flaws into a piece of attack code, throw it out there, and see what sticks to systems," she told El Reg. "Given the updating habits of too many many security-software users, something usually gets through." ®

Beginner's guide to SSL certificates

More from The Register

next story
FYI: OS X Yosemite's Spotlight tells Apple EVERYTHING you're looking for
It's on by default – didn't you read the small print?
Russian hackers exploit 'Sandworm' bug 'to spy on NATO, EU PCs'
Fix imminent from Microsoft for Vista, Server 2008, other stuff
Microsoft pulls another dodgy patch
Redmond makes a hash of hashing add-on
'LulzSec leader Aush0k' found to be naughty boy not worthy of jail
15 months home detention leaves egg on feds' faces as they grab for more power
China is ALREADY spying on Apple iCloud users, claims watchdog
Attack harvests users' info at iPhone 6 launch
Carders punch holes through Staples
Investigation launched into East Coast stores
Kill off SSL 3.0 NOW: HTTPS savaged by vicious POODLE
Pull it out ASAP, it is SWISS CHEESE
prev story

Whitepapers

Forging a new future with identity relationship management
Learn about ForgeRock's next generation IRM platform and how it is designed to empower CEOS's and enterprises to engage with consumers.
Cloud and hybrid-cloud data protection for VMware
Learn how quick and easy it is to configure backups and perform restores for VMware environments.
Three 1TB solid state scorchers up for grabs
Big SSDs can be expensive but think big and think free because you could be the lucky winner of one of three 1TB Samsung SSD 840 EVO drives that we’re giving away worth over £300 apiece.
Reg Reader Research: SaaS based Email and Office Productivity Tools
Read this Reg reader report which provides advice and guidance for SMBs towards the use of SaaS based email and Office productivity tools.
Security for virtualized datacentres
Legacy security solutions are inefficient due to the architectural differences between physical and virtual environments.