Feeds

Google Chrome has voice-snoop bug, claims developer

Sneaky microphone switch-on popunder demo published

Beginner's guide to SSL certificates

A frustrated developer claims that Google is sitting on a bug that would expose voice search to eavesdroppers, and has released exploit code on github.

Tal Ater, whose speciality is speech recognition, claims in this blog post that a site can plant script in Chrome that will allow an attacker to turn on the microphone of a visitor to a site – and leave it open for as long as Chrome remains open.

He has posted the code to github.

When it's working right, Chrome's voice search allows a visitor to any site to ask for voice control, at which point the microphone is turned on – and the user gets a clear indication that this has happened, Ater writes. This choice is also remembered for the future.

However, he says, a malicious site could exploit this by opening "popunders" that users aren't aware of. Here's his description of how this works:

“When you click the button to start or stop the speech recognition on the site, what you won’t notice is that the site may have also opened another hidden popunder window. This window can wait until the main site is closed, and then start listening in without asking for permission. This can be done in a window that you never saw, never interacted with, and probably didn’t even know was there.”

The popunder can also be disguised as (for example) a banner ad – and it won't show the indication that the microphone is listening.

Ater has posted this demonstration to YouTube:

Youtube Video

Ater claims he notified Google about the flaw in September 2013, but that Google is waiting on “ongoing” discussions at the W3C before it acts on the bug. The Register has asked Google for a response. ®

Internet Security Threat Report 2014

More from The Register

next story
Webcam hacker pervs in MASS HOME INVASION
You thought you were all alone? Nope – change your password, says ICO
You really need to do some tech support for Aunty Agnes
Free anti-virus software, expires, stops updating and p0wns the world
Meet OneRNG: a fully-open entropy generator for a paranoid age
Kiwis to seek random investors for crowd-funded randomiser
USB coding anarchy: Consider all sticks licked
Thumb drive design ruled by almighty buck
Attack reveals 81 percent of Tor users but admins call for calm
Cisco Netflow a handy tool for cheapskate attackers
Privacy bods offer GOV SPY VICTIMS a FREE SPYWARE SNIFFER
Looks for gov malware that evades most antivirus
Patch NOW! Microsoft slings emergency bug fix at Windows admins
Vulnerability promotes lusers to domain overlords ... oops
prev story

Whitepapers

Choosing cloud Backup services
Demystify how you can address your data protection needs in your small- to medium-sized business and select the best online backup service to meet your needs.
Forging a new future with identity relationship management
Learn about ForgeRock's next generation IRM platform and how it is designed to empower CEOS's and enterprises to engage with consumers.
Reg Reader Research: SaaS based Email and Office Productivity Tools
Read this Reg reader report which provides advice and guidance for SMBs towards the use of SaaS based email and Office productivity tools.
The hidden costs of self-signed SSL certificates
Exploring the true TCO for self-signed SSL certificates, including a side-by-side comparison of a self-signed architecture versus working with a third-party SSL vendor.
Top 5 reasons to deploy VMware with Tegile
Data demand and the rise of virtualization is challenging IT teams to deliver storage performance, scalability and capacity that can keep up, while maximizing efficiency.