Close Menu
Kickstarter Comic
  • Home
  • kickstarter
  • kickstarter game
  • kickstarter comic
  • kickstarter card game
  • kickstarter comic book
  • Comic

Subscribe to Updates

Get the latest creative news from FooBar about art, design and business.

What's Hot

Review: Under the tree when no one is watching #1

March 7, 2026

Review: Darkstalkers x Street Fighter: Hunter Killers #1

March 1, 2026

Review: Ghosted #2 (2013)

February 26, 2026
Facebook X (Twitter) Instagram
Kickstarter Comic
  • Home
  • About Us
  • Advertise with Us
  • DMCA Policy
  • Privacy Policy
  • Terms & Conditions
  • Home
  • kickstarter
  • kickstarter game
  • kickstarter comic
  • kickstarter card game
  • kickstarter comic book
  • Comic
Kickstarter Comic
Home » Arc Browser, which allows users to customize websites, has a critical vulnerability
kickstarter comic

Arc Browser, which allows users to customize websites, has a critical vulnerability

matthewephotography@yahoo.comBy matthewephotography@yahoo.comSeptember 21, 2024No Comments2 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Email
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link


One of the features that differentiates Arc Browser from other browsers is its ability to customize websites. Called “Boost,” the feature allows users to change the background color of a website, switch to a more preferred or readable font, or even remove unwanted elements from the page entirely. The changes you make aren’t supposed to be visible to others, but can be shared across devices. Now, the Browser Company, creators of Arc, have acknowledged that security researchers have found a critical flaw that could allow attackers to use Boost to compromise a target’s system.

The company used Firebase, which the security researcher known as “xyzeva” described in his vulnerability post as a “database as a backend service” to support some of the Arc features. In particular, for Boosts, it’s used to share and sync customizations across devices. In xyzeva’s post, he showed how the browser can load Boosts onto a device using the creator’s identity (creatorID). He also showed how to change that element to the target’s identity tag and assign the Boosts you create to that target.

For example, if a bad actor creates a boost containing a malicious payload, they can simply change their own creator ID to that of the intended target. Then, when the intended victim visits a website with Arc, they could unknowingly download the hacker’s malware. And as the researchers explained, it’s very easy to obtain a browser’s user ID. A user who refers someone to Arc will share their ID with the recipient, and if the account was created from a referral, the referrer will also get their ID. Users can also share their boosts with others. Arc has a page of public boosts that includes the creator ID of the person who created the boost.

In a post, the browser company said it was notified of the security issue by xyzeva on August 25 and released a fix the next day with the help of the researcher. It also assured users that no one had exploited the vulnerability and no users were affected. The company has also implemented several security measures to prevent a similar situation, including migrating away from Firebase, disabling JavaScript by default in synced Boosts, establishing a bug bounty program, and hiring a new senior security engineer.



Source link

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
matthewephotography@yahoo.com
  • Website

Related Posts

Tesla’s “Robotaxi” brand may be too common for trademarks

May 7, 2025

Know what time this cool asteroid clock is

January 28, 2025

Get more than $ 400 from one of our favorite alien wear game monitors

January 28, 2025
Leave A Reply Cancel Reply

Top Posts

Transformers #22 Review

July 8, 202529 Views

Comic Book Review: Doctor Who #1 (2020)

December 21, 202429 Views

Transformers #21 Review

June 11, 202521 Views

Comic Review: X-Force #59 (1996)

December 20, 202421 Views
Don't Miss
kickstarter comic book

Review: Under the tree when no one is watching #1

Image credit: IDW Comics Cozy horror with anthropomorphic animals? Looks like it’ll handle itself just…

Review: Darkstalkers x Street Fighter: Hunter Killers #1

March 1, 2026

Review: Ghosted #2 (2013)

February 26, 2026

Review: Godzilla (Kaisei Era) #2 (2025)

February 25, 2026
About Us
About Us

Welcome to KickstarterComic.com!

At KickstarterComic.com, we’re passionate about bringing the latest and greatest in Kickstarter-funded games and comics to the forefront. Our mission is to be your go-to resource for discovering and exploring the exciting world of crowdfunding campaigns for board games, card games, comic books, and more.

Facebook X (Twitter) Pinterest YouTube WhatsApp
Our Picks

Review: Under the tree when no one is watching #1

March 7, 2026

Review: Darkstalkers x Street Fighter: Hunter Killers #1

March 1, 2026

Review: Ghosted #2 (2013)

February 26, 2026
Most Popular

The best gaming laptops for 2024

September 19, 20240 Views

Iranian hackers tried to leak Trump information to the Biden campaign

September 19, 20240 Views

EU gives Apple six months to ease interoperability between devices

September 19, 20240 Views
  • Home
  • About Us
  • Advertise with Us
  • DMCA Policy
  • Privacy Policy
  • Terms & Conditions
© 2026 kickstartercomic. Designed by kickstartercomic.

Type above and press Enter to search. Press Esc to cancel.