Skip to content
Privacy & Security

Yahoo Manages to Leak Private Security Key With New Chrome Extension

By

Reading time 1 minute

Comments (0)

Yahoo has just released its Axis extension—a visual search tool that links across desktop and mobile devices—but sadly, there’s a hitch. During the release, Yahoo managed to leak a private security key in its Chrome version, that could allow anyone to create malicious plugins masquerading as official software. Oops.

https://gizmodo.com/yahoo-launches-axis-browser-for-ios-and-chrome-and-it-5912873

The Register reports that Nik Cubrilovic revealed the mistake on his blog, explaining that users should not install the extension “until the issue is clarified”. Hidden amongst the Chrome source code of the of the Axis extension is a private, unencrypted certificate, which allows Yahoo to sign the app, in the process proving it genuine. But it shouldn’t be visible to users. Because it is, there’s nothing stopping people from copying it and including it in malicious software, which could trick Google into thinking it was legitimate.

Fortunately, Yahoo has since posted a replacement version of the extension without the problem. Still, Yahoo: don’t you think it’s time you got a grip? [The Register]

https://gizmodo.com/how-yahoo-killed-flickr-and-lost-the-internet-5910223

Explore more on these topics

Share this story

Sign up for our newsletters

Subscribe and interact with our community, get up to date with our customised Newsletters and much more.