SUBSCRIBE
Tech Journal Now
  • Home
  • News
  • AI
  • Reviews
  • Guides
  • Best Buy
  • Software
  • Games
Reading: Google patches Chrome vulnerability used for account takeover and MFA bypass
Share
Tech Journal NowTech Journal Now
Font ResizerAa
  • News
  • Reviews
  • Guides
  • AI
  • Best Buy
  • Games
  • Software
Search
  • Home
  • News
  • AI
  • Reviews
  • Guides
  • Best Buy
  • Software
  • Games
Have an existing account? Sign In
Follow US
© Foxiz News Network. Ruby Design Company. All Rights Reserved.
Tech Journal Now > Software > Google patches Chrome vulnerability used for account takeover and MFA bypass
Software

Google patches Chrome vulnerability used for account takeover and MFA bypass

News Room
Last updated: May 15, 2025 9:06 pm
News Room
Share
1 Min Read
SHARE

“Unlike other browsers, Chrome resolves the Link header on subresource requests. But what’s the problem? The issue is that the Link header can set a referrer-policy. We can specify unsafe-url and capture the full query parameters,” he wrote.

Link headers are used by websites to tell a browser about important page resources, for example, images, that it should preload. As part of the HTTP response that happens before the browser encounters any HTML, this accelerates response times. When the browser goes hunting for the resource, usually on a third-party server, it transmits a URL containing information about the requesting site, as allowed by the referrer-policy.

Unfortunately, in Chrome this URL can also include information with a bearing on security, such as OAuth flows used for authentication.

Read the full article here

You Might Also Like

Nvidia, xAI and two energy giants join genAI infrastructure initiative

Microsoft OneDrive move may facilitate accidental sensitive file exfiltration

At 50, Microsoft highlights AI and Copilot as the company’s future – Computerworld

Relying on file storage heritage, Box pivots to AI – Computerworld

Real-world use cases for agentic AI – Computerworld

Share This Article
Facebook Twitter Email Print
Leave a comment Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

- Advertisement -
Ad image

Trending Stories

Games

Civil war breaks out in Helldivers 2 as players spawn infinite mechs to crash each other’s games

May 15, 2025
Games

Avowed lets you replace spiders with orbs in the first of its major updates coming this year

May 15, 2025
News

Freight company DAT acquires Seattle fintech startup Outgo

May 15, 2025
Games

Hideo Kojima says most Death Stranding playtesters told him ‘it was a terrible game,’ and he’s a little bummed Death Stranding 2 is testing way better

May 15, 2025
Games

After hearing the king of funny Elder Scrolls clips explain how Oblivion NPCs work, I have a newfound respect for elves who steal food when they’re hungry and husbands who fight their wives’ dogs

May 15, 2025
AI

US companies are helping Saudi Arabia to build an AI powerhouse – Computerworld

May 15, 2025

Always Stay Up to Date

Subscribe to our newsletter to get our newest articles instantly!

Follow US on Social Media

Facebook Youtube Steam Twitch Unity

2024 © Prices.com LLC. All Rights Reserved.

Tech Journal Now

Quick Links

  • Privacy Policy
  • Terms of use
  • For Advertisers
  • Contact
Welcome Back!

Sign in to your account

Username or Email Address
Password

Lost your password?