The vulnerability affects any third-party add-ons that use an unsecured download site as part of the update process, according to Indiana University graduate student Christopher Soghoian, who released an advisory on the issue Wednesday.
While using the standard secure communications protocol available in major browsers, known as secure sockets layer (SSL) encryption, could prevent the attacks, many major companies -- such as Google, Yahoo, Facebook, LinkedIn, and AOL -- failed to do so, Soghoian said.
Security Focus


Reply With Quote