Chrome Bug Lets Sites Record Audio and Video Without Indicating

Bot

AI-powered Bot
Thread author
Apr 21, 2016
4,370
A bug within Google Chrome allows websites to record audio and video without any indicators regarding this activity.

The discovery was made by an AOL web developer by the name of Ran Bar-Zik, Bleeping Computer reports. While the bug may seem of massive proportions, it actually isn't all that bad because the malicious website still needs to get the user's permission to access the audio and video components. Therefore, if the user doesn't grant the website the right to listen in, it won't do that.

However, the problem is there and there are ways to weaponize the vulnerability.

How it works
The discovery was reportedly made as the AOL developer was dealing with a website running WebRTC code, which is the protocol for streaming audio and video in real time.

If permission is granted for the website to access the audio and video components, most likely unknowingly as the user tries to dismiss the notification, the website can run JavaScript code that records audio or video content. The content can then be sent over the Internet to the other participants of the stream.

Read more: Chrome Bug Lets Sites Record Audio and Video Without Indicating
 

Ink

Administrator
Verified
Jan 8, 2011
22,490
I'm starting to worry with all of these bugs coming out with google/chrome
You can globally block these permissions in the settings:
upload_2017-5-30_16-48-24.png

Example:
upload_2017-5-30_16-50-35.png

Alternatively, if you NEVER use your Mic or Camera, you can Disable via Device Manager or Uninstall (not recommended).

Not sure about "video".
 

Dean Winchestere

Level 2
Verified
Mar 9, 2017
50
This is another reason why I disable WebRTC. All it does is open holes for privacy invasion. It also leaks real ip if using a VPN.
 
  • Like
Reactions: Weebarra

soccer97

Level 11
Verified
May 22, 2014
517
Some PC's have the ability to disable the webcam in the system BIOS at startup as well. Hopefully a fix will be pushed out by Chrome 60.

Thanks Spawn - in addition you can go to Control Panel > Flash Player and do the same thing - which will affect other browsers if they are actually affected in the future
 

Entreri

Level 7
Verified
May 25, 2015
342
That is bad. At least for my laptop, I taped over and disabled microphone via reg edit.

I previously disabled them both via device manager, but M$ (Win10), enabled them after some time.
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top