Advertisement
Advertisement

So even if you only input your information the text boxes you saw, Chrome could have autofilled hidden boxes with more sensitive material. And because the site would have to be laid out specifically to hide boxes, you wouldn’t necessarily notice that the information was being sent. That’s not good if the data includes credit card information.

In the replies to the original tweet, other users suggested simple fixes to the affected browsers, like notifying users what information they’ve filled in before submitting or simply restricting autofill to only visible boxes. For now, the easiest way to avoid the exploit is simply to disable your autofill feature.

Disabling autofill on Chrome is accessed first by clicking Preferences and then Show Advanced Settings. You can also go to chrome://settings/. From there, you just uncheck the box:

Advertisement

Disabling autofill on Safari is accessed first via Preferences and then by going to the ‘AutoFill’ tab and unchecking the boxes.

Advertisement

Firefox requires manual autofill for text boxes, meaning you have to at least hover over a text box before it’s filled in. That means the exploit won’t work as well in the browser, since you can’t fill in the boxes you can’t see.

We reached out to Apple and Google for comment on Kuosmanen’s exploit and how to avoid it. We’ll update this post if we hear back.

Advertisement

[The Guardian]

Update: 1/13/17 3pm ET: After publication, a Google rep reached out to say the company is “aware of the issue and working to address it.”