Google fixes Chrome issue that allowed theft of WiFi logins

Status
Not open for further replies.

Venustus

Level 59
Thread author
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Dec 30, 2012
4,809
The latest version of the Chrome browser, version 69, released yesterday, includes a critical patch for a design issue that an attacker could exploit to steal WiFi logins from home or corporate networks.
The issue is that older versions of Chrome would auto-fill usernames and passwords in login forms loaded via HTTP.
Elliot Thompson, a researcher with UK cyber-security firm SureCloud, put together a technique that exploits this design issue in a complex multi-step attack through which he was able to steal WiFi login data, something that Chrome doesn't even handle in the first place.
His attack, which he named Wi-Jacking (also WiFi Jacking), works with Chrome on Windows. The steps for executing a Wi-Jacking attack are detailed below:

More
 
Status
Not open for further replies.

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top