• Home
  • Insight
  • Blog
  • Business
  • Entertainment
  • Health
  • Politics
  • Shop
    • Gift Shop
    • Value Shop
    • Store
    • Bargain Shop
    • Discount
  • Sports
  • Tech
  • Travel
  • USA
  • Video
  • World
    • Asia
    • Africa
    • South America
    • North America
    • Europe
    • Oceania
Sunday, September 20, 2026
No Result
View All Result
Subscribe Now
  • Home
  • Insight
  • Blog
  • Business
  • Entertainment
  • Health
  • Politics
  • Shop
    • Gift Shop
    • Value Shop
    • Store
    • Bargain Shop
    • Discount
  • Sports
  • Tech
  • Travel
  • USA

    Court squashes Reese’s faceless pumpkin lawsuit

    MS NOW, CNN, Politico reporters barred from White House after Trump announces ban

    Trump and GOP Will Face a ‘Reckoning’ this November

    Bo Bichette’s willingness to change positions could reshape Mets’ infield

    Heavy snow is crucial to recharge state’s groundwater, study finds

    This Arizona medical examiner is tracking heat-related deaths : NPR

    South Florida woman accused of drugging man at club to steal Rolex

    Trump Approves $2.8 Billion Arms Sale to Israel, Including 40,000 One-Ton Bombs

    Tech CEOs’ Doomsaying Is a Distraction from Real, Existing Harms of AI

  • Video
  • World
    • Asia
    • Africa
    • South America
    • North America
    • Europe
    • Oceania
The Insight Post
  • Home
  • Insight
  • Blog
  • Business
  • Entertainment
  • Health
  • Politics
  • Shop
    • Gift Shop
    • Value Shop
    • Store
    • Bargain Shop
    • Discount
  • Sports
  • Tech
  • Travel
  • USA

    Court squashes Reese’s faceless pumpkin lawsuit

    MS NOW, CNN, Politico reporters barred from White House after Trump announces ban

    Trump and GOP Will Face a ‘Reckoning’ this November

    Bo Bichette’s willingness to change positions could reshape Mets’ infield

    Heavy snow is crucial to recharge state’s groundwater, study finds

    This Arizona medical examiner is tracking heat-related deaths : NPR

    South Florida woman accused of drugging man at club to steal Rolex

    Trump Approves $2.8 Billion Arms Sale to Israel, Including 40,000 One-Ton Bombs

    Tech CEOs’ Doomsaying Is a Distraction from Real, Existing Harms of AI

  • Video
  • World
    • Asia
    • Africa
    • South America
    • North America
    • Europe
    • Oceania
No Result
View All Result
No Result
View All Result
Home Tech

Zero-day used to infect Chrome users could pose threat to Edge and Safari users, too

by Theinsightpost
July 21, 2022
in Tech
0 0
0
Zero-day used to infect Chrome users could pose threat to Edge and Safari users, too


A secretive seller of cyberattack software recently exploited a previously unknown Chrome vulnerability and two other zero-days in campaigns that covertly infected journalists and other targets with sophisticated spyware, security researchers said.

CVE-2022-2294, as the vulnerability is tracked, stems from memory corruption flaws in Web Real-Time Communications, an open source project that provides JavaScript programming interfaces to enable real-time voice, text, and video communications capabilities between web browsers and devices. Google patched the flaw on July 4 after researchers from security firm Avast privately notified the company it was being exploited in watering hole attacks, which infect targeted websites with malware in hopes of then infecting frequent users. Microsoft and Apple have since patched the same WebRTC flaw in their Edge and Safari browsers, respectively.

Avast said on Thursday that it uncovered multiple attack campaigns, each delivering the exploit in its own way to Chrome users in Lebanon, Turkey, Yemen, and Palestine. The watering hole sites were highly selective in choosing which visitors to infect. Once the watering hole sites successfully exploited the vulnerability, they used their access to install DevilsTongue, the name Microsoft gave last year to advanced malware sold by an Israel-based company named Candiru.

“In Lebanon, the attackers seem to have compromised a website used by employees of a news agency,” Avast researcher Jan Vojtěšek wrote. “We can’t say for sure what the attackers might have been after, however often the reason why attackers go after journalists is to spy on them and the stories they’re working on directly, or to get to their sources and gather compromising information and sensitive data they shared with the press.”

Advertisement

Vojtěšek said Candiru had been lying low following exposes published last July by Microsoft and CitizenLab. The researcher said the company reemerged from the shadows in March with an updated toolset. The watering hole site, which Avast didn’t identify, took pains not only in selecting only certain visitors to infect but also in preventing its precious zero-day vulnerabilities from being discovered by researchers or potential rival hackers.

Vojtěšek wrote:

Interestingly, the compromised website contained artifacts of persistent XSS attacks, with there being pages that contained calls to the Javascript function alert along with keywords like “test.” We suppose that this is how the attackers tested the XSS vulnerability, before ultimately exploiting it for real by injecting a piece of code that loads malicious Javascript from an attacker-controlled domain. This injected code was then responsible for routing the intended victims (and only the intended victims) to the exploit server, through several other attacker-controlled domains.

The malicious code injected into the compromised website, loading further Javascript from stylishblock[.]com
Enlarge / The malicious code injected into the compromised website, loading further Javascript from stylishblock[.]com

Avast

Once the victim gets to the exploit server, Candiru gathers more information. A profile of the victim’s browser, consisting of about 50 data points, is collected and sent to the attackers. The collected information includes the victim’s language, timezone, screen information, device type, browser plugins, referrer, device memory, cookie functionality, and more. We suppose this was done to further protect the exploit and make sure that it only gets delivered to the targeted victims. If the collected data satisfies the exploit server, it uses RSA-2048 to exchange an encryption key with the victim. This encryption key is used with AES-256-CBC to establish an encrypted channel through which the zero-day exploits get delivered to the victim. This encrypted channel is set up on top of TLS, effectively hiding the exploits even from those who would be decrypting the TLS session in order to capture plaintext HTTP traffic.

Despite the efforts to keep CVE-2022-2294 secret, Avast managed to recover the attack code, which exploited a heap overflow in WebRTC to execute malicious shellcode inside a renderer process. The recovery allowed Avast to identify the vulnerability and report it to developers so it could be fixed. The security firm was unable to obtain a separate zero-day exploit that was required so the first exploit could escape Chrome’s security sandbox. That means this second zero-day will live to fight another day.

Advertisement

Once DevilsTongue got installed, it attempted to elevate its system privileges by installing a Windows driver containing yet another unpatched vulnerability, bringing the number of zero-days exploited in this campaign to at least three. Once the unidentified driver was installed, DevilsTongue would exploit the security flaw to gain access to the kernel, the most sensitive part of any operating system. Security researchers call the technique BYOVD, short for “bring your own vulnerable driver.” It allows malware to defeat OS defenses since most drivers automatically have access to an OS kernel.

Avast has reported the flaw to the driver maker, but there’s no indication that a patch has been released. As of publication time, only Avast and one other antivirus engine detected the driver exploit.

Since both Google and Microsoft patched CVE-2022-2294 in early July, chances are good that most Chrome and Edge users are already protected. Apple, however, fixed the vulnerability on Wednesday, meaning Safari users should make sure their browsers are up to date.

“While there is no way for us to know for certain whether or not the WebRTC vulnerability was exploited by other groups as well, it is a possibility,” Vojtěšek wrote. “Sometimes zero-days get independently discovered by multiple groups, sometimes someone sells the same vulnerability/exploit to multiple groups, etc. But we have no indication that there is another group exploiting this same zero-day.”



Source link

ShareTweetSend
Previous Post

GOP Senators Snookered Into Schumer’s Pork Barrel Politics

Next Post

Sports News: World and National Sports Headlines, Score Updates, Highlights, Stats & Results

Related News

Tech

Not all AI workers think the tech could kill everyone

September 19, 2026
Tech

4 Strategies to Battle ‘Techflation’

September 19, 2026
Tech

LLMs respond differently to harmful prompts when AI watermarking is used

September 18, 2026
Tech

CFTC Draws a No-Custody Line for Trading Software

September 18, 2026
Next Post
Sports News: World and National Sports Headlines, Score Updates, Highlights, Stats & Results

Sports News: World and National Sports Headlines, Score Updates, Highlights, Stats & Results

Discussion about this post

Subscribe To Our Newsletters

    Customer Support


    1251 Wilcrest Drive
    Houston, Texas
    77042 USA
    Call-832.795.1420
    e-mail – news@theinsightpost.com

    Subscribe To Our Newsletters

      Categories

      • Africa
      • Africa-East
      • African Sports
      • American Sports
      • Arts
      • Asia
      • Australia
      • Business
      • Business Asia
      • Business- Africa
      • Canada
      • Defense
      • Education
      • Egypt
      • Energy
      • Entertainment
      • Europe
      • European Soccer
      • Finance
      • Germany
      • Ghana
      • Health
      • Insight
      • International
      • Investing
      • Japan
      • Latest Headlines
      • Life & Living
      • Markets
      • Mobile
      • Movies
      • New Zealand
      • Nigeria
      • Politics
      • Scholarships
      • Science
      • South Africa
      • South America
      • Sports
      • Tech
      • Travel
      • UK
      • USA
      • Weather
      • World
      No Result
      View All Result

      Recent News

      Seton Hall national security program boasts 80% government placement rate

      September 20, 2026

      ‘She’s Back — Aunt Jordan Strikes Again’

      September 20, 2026

      Can Kevin Warsh Change the Federal Reserve?

      September 20, 2026

      Gavin Newsom and Jake Tapper Fly Fishing Mocked by Wildlife Experts

      September 20, 2026
      • Home
      • Advertise With Us
      • About Us
      • Corporate
      • Consumer Rewards
      • Forum
      • Privacy Policy
      • Social Trends

      Theinsightpost ©2026 | All Rights Reserved. Theinsightpost is an Elnegy LLC company, registered in Texas, USA

      Welcome Back!

      Login to your account below

      Forgotten Password?

      Retrieve your password

      Please enter your username or email address to reset your password.

      Log In

      Add New Playlist

      We are using cookies to give you the best experience on our website.

      You can find out more about which cookies we are using or switch them off in .

      No Result
      View All Result
      • Home
      • Insight
      • Blog
      • Business
      • Entertainment
      • Health
      • Politics
      • Shop
        • Gift Shop
        • Value Shop
        • Store
        • Bargain Shop
        • Discount
      • Sports
      • Tech
      • Travel
      • USA
      • Video
      • World
        • Asia
        • Africa
        • South America
        • North America
        • Europe
        • Oceania

      Theinsightpost ©2026 | All Rights Reserved. Theinsightpost is an Elnegy LLC company, registered in Texas, USA

      The Insight Post
      Powered by  GDPR Cookie Compliance
      Privacy Overview

      This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.

      Strictly Necessary Cookies

      Strictly Necessary Cookie should be enabled at all times so that we can save your preferences for cookie settings.

      Cookie Policy

      More information about our Cookie Policy