Search
Close this search box.
Search
Close this search box.

Beware! 2.5 Billion Google Chrome Users are at Risk

Chrome Users Under Risk

Google Chrome is a web browser that is used by billions of people all over the world. Imperva Red, a cyber security company, found a security flaw in Google Chrome and Chromium-based browsers. This puts the data of more than 2.5 billion users at risk.

This flaw, which the company calls CVE-2022-3656, made it possible for sensitive files, like crypto wallets and cloud provider credentials, to be stolen.

Read More: Google Cloud AI Tools for Retailers

“The vulnerability was found through a review of how the browser interacts with the file system. Specifically, the review looked for common flaws in how browsers handle symlinks,” the blog says.

What is a Symlink?

A symbolic link, or symlink, is what Imperva Red calls a file that points to another file or directory. It tells the operating system that the linked file or directory should be treated as if it were at the location of the symlink. It says that a symlink can be used to make shortcuts, change the path to a file, or arrange files in a more flexible way.

But if these links are not handled properly, they can also be used to open security holes.

In the case of Google Chrome, the problem was caused by how the browser handled symlinks when it worked with files and directories. In particular, the browser didn’t check if the symlink pointing to a place that wasn’t meant to be accessible. This made it possible for sensitive files to be stolen, as explained in the blog post.

How Symlinks Affected Google Chrome?

The company says that an attacker could make a fake website that offers a new crypto wallet service. This is how the vulnerability affected Google Chrome. The website could then trick the user into making a new wallet by asking them to download their “recovery” keys.

Read Also: OpenAI Working on Paid Pro ChatGPT Version

These keys would actually be a zip file that contained a symlink to a private file or folder on the user’s computer, such as a cloud provider password. “When the user unzips and submits the “recovery” keys back to the website, the symlink is processed, and the attacker has access to the sensitive file,” the researchers write. blog says.

What should Chrome Users do?

Imperva Red says it told Google about the security hole, and the problem was fixed in Chrome 108. Users should always keep their software up to date to protect themselves from these kinds of weaknesses.


Subscribe to Our Newsletter

Related Articles

Top Trending

teresa fidalgo
The Real Teresa Fidalgo Story: Ghost or True? Watch on Instagram, YouTube, Quora
Pixel Art Games
Why Pixel Art Games Are Still Thriving in 2025?
Hosting Services That Offer Malware Removal
Top 5 Hosting Services That Offer Malware Removal & Scanning
Kimi Rutledge's Journey To Stardom
Behind the Scenes with Kimi Rutledge, the Breakout Star of Obliterated
Properties in Italy with Stone Fireplaces
Top 10 Properties in Italy with Stone Fireplaces

LIFESTYLE

lovelolablog code
Unlock Exclusive Lovelolablog Code For Discount Deals in 2025
Sustainable Kiwi Beauty Products
10 Sustainable Kiwi Beauty Products You Should Try for a Greener Routine
Best E-Bikes for Seniors
Best E-Bikes for Seniors with Comfort and Safety in Mind
wellhealthorganic.com effective natural beauty tips
Top 5 Well Health Organic Beauty Tips for Glowing Skin
Chemical-Free Alternatives to Your Favorite Beauty Products
7 Chemical-Free Alternatives to Your Favorite Beauty Products You Need to Try

Entertainment

teresa fidalgo
The Real Teresa Fidalgo Story: Ghost or True? Watch on Instagram, YouTube, Quora
Kimi Rutledge's Journey To Stardom
Behind the Scenes with Kimi Rutledge, the Breakout Star of Obliterated
nene leakes net worth
Nene Leakes Net Worth 2025: Unveiling The Latest Figures
bader shammas net worth
Bader Shammas Net Worth: How Lindsay Lohan's Husband Makes $100 Million
Nick Carter sexual assault lawsuit 2025
Nick Carter Faces 4th Sexual Assault Lawsuit Over Rape, STD Claims

GAMING

Pixel Art Games
Why Pixel Art Games Are Still Thriving in 2025?
Most Unfair Levels In Gaming History
The Most Unfair Levels In Gaming History
Gacha Games
Top 10 Gacha Games That Are Actually Worth Playing
How Live Betting Works & Who Decides the Odds
How Live Betting Works & Who Decides the Odds?
ovo unblocked
Ovo Unblocked Games: Popular Features, Tips, and Similar Games

BUSINESS

South Korea chip sector relief US tariff fears
Seoul Responds to U.S. Tariffs with $4.9B Semiconductor Aid
hong kong us mail ban trump tariff hike
Hong Kong Postal Ban Hits US Amid Escalating Trade War
Role Of ULIPs In Retirement Planning In India
ULIPs in Retirement Planning: Smart Investment for Indian Retirees
Top 10 Strongest Currencies in Africa in 2025
Top 10 Strongest Currencies in Africa in 2025: Updated Ranking
Jesús Ricardo Álvarez Gualtieri comparte la experiencia positiva de la robótica en la industria de PVC
Jesús Ricardo Álvarez Gualtieri Shares the Positive Experience of Robotics in the PVC Industry

TECHNOLOGY

Rise of Fractional NFTs
How Fractionalized NFTs Are Making High-Value Assets More Accessible?
How to Build Cross-Chain Web3 Applications
How to Build Cross-Chain Web3 Applications?
How to Create a Web3 dApp
How to Create a Web3 dApp With Zero Coding Experience?
How to Use DeFi Lending Protocols Safely
How to Use DeFi Lending Protocols Safely in 2025?
claude ai searches google workspace automatically
Claude AI Now Searches Your Entire Google Workspace Automatically

HEALTH

Back Pain In Athletes
Back Pain In Athletes: Prevention And Recovery Strategies
Sinclair Method
What is the Sinclair Method?
Small Things Neurologists Wish You’d Do For Your Brain
10 Small Things Neurologists Wish You’d Do For Your Brain
Ways Gaming Can Actually Improve Your Mental Health
Top 10 Ways Gaming Can Actually Improve Your Mental Health
Benefits of Single Case Agreements for Patients
Benefits of Single Case Agreements for Patients & Providers