Chrome vulnerability could have led to widespread data theft

andranik123 – stock.adobe.com

A dangerous vulnerability in Google Chrome and Chromium-based browsers could have put billions of users’ files at risk of being stolen

Alex Scroxton

By

Published: 12 Jan 2023 11:03

Researchers at Imperva have revealed their hand in uncovering and fixing a potentially dangerous vulnerability in Google’s Chrome and Chromium-based browsers that, left untreated, could have enabled threat actors to steal sensitive files from more than 2.5 billion worldwide users of the web browsing technology.

Tracked as CVE-2022-3656, the vulnerability was first uncovered in 2022 by Imperva’s red team, which was looking into how the browser interacts with the file system, specifically in how browsers process symbolic links – also known as symlinks.

Symlinks are files that point to another file or directory, which enable the operating system to treat the linked file as if it were present at the symlink’s location. They are used for creating shortcuts, redirecting file paths, or better organising files, explained Imperva’s Ron Masas, who is credited with discovering the bug.

“In the case of the vulnerability we disclosed to Google, the issue arose from the way the browser interacted with symlinks when processing files and directories,” explained Masas in his write-up.

“Specifically, the browser did not properly check if the symlink was pointing to a location that was not intended to be accessible, which allowed for the theft of sensitive files. This issue is commonly known as symbolic link following.”

In one potential attack scenario exploiting CVE-2022-3656, an attacker could create a fake website to offer a crypto wallet service, tricking the user into creating a new wallet by downloading supposed recovery keys in the form of zip file, which in fact contained a symlink to a sensitive file or folder on the user’s computer, such as a cloud service credential.

If the file was unzipped and the malicious recovery keys uploaded back to the website, the symlink would be processed and the attacker would gain access to the sensitive file.

In such a scenario, the victim may not even notice they had been tricked, since a great many crypto wallets or other online services require their users to download recovery keys to serve as backups should they lose access to their account, perhaps because they had forgotten their password.

Masas was able to create a proof-of-concept attack using CSS to manipulate the file input element in the browser. When the file input element was made larger, he was able to ensure any file dropped onto the page would be uploaded, which in turn let him exploit the symlink vulnerability to exfiltrate files.

He noted that cyber criminals are increasingly targeting people holding cryptocurrencies by exploiting software vulnerabilities to access their wallets and steal funds, so if using Chrome or a Chromium-based browser – such as Microsoft Edge – it is important to keep them up to date, and to exercise increased diligence when downloading files. Users may also wish to consider using a hardware wallet to store crypto assets, and improving the security of their credentials with password managers or multifactor authentication (MFA).

Masas reported the symlink vulnerability to Google, which issued a fix in the Chrome 107 update on 25 October 2022. However, when Masas and his team tested this out, they found that the issue was not fully addressed. It has now been fully resolved in the Chrome 108 update, which was released on 29 November (note this additional fix is not disclosed in Google’s official release update).

“We would like to thank Google for their response to this issue and for their cooperation in addressing it,” said Masas.

“It was a privilege to work with the Google team and help make Chrome a safer and more secure browser for all users. We take pride in our ability to identify and disclose vulnerabilities, and we are committed to working with software vendors to ensure that the products we all rely on are as secure as possible.”

Read more on Application security and coding requirements

Read More
Tami Mcnaught

Latest

AIONOS Highlights Enterprise AI Vision for APAC at GITEX AI ASIA 2026

SINGAPORE, Apr 10, 2026 - (ACN Newswire) - AIONOS, a Singapore-based enterprise AI company backed by InterGlobe Enterprises and Assago Group, is making a strong presence at GITEX AI ASIA 2026, taking place from 9 to 10 April at Marina Bay Sands, Singapore. The company’s participation reflects its increasing investment in the Asia Pacific region

‘I Was Immediately Admitted’ – Junior Pope’s Wife Recounts Husband’s Devastating Death

The wife of late Nollywood actor, JohnPaul Odonwodo, popularly known as Junior Pope , Jennifer Odonwodo, has recounted the devastating moment she received news of his death. Naija News reports that Jennifer, in a post via her Instagram page on Friday, described the incident as “the most devastating call” of her life and had assumed

NASA prepares for Artemis 2 return

WASHINGTON — The Artemis 2 mission is set for a final, fiery test when the spacecraft reenters April 10 ahead of a splashdown off the California coast. Artemis 2 will wrap up a mission lasting a little more than nine days with a tightly choreographed sequence of events in the mission’s final hour. It starts

CDL Launches $1.6B Perpetual Securities Programme and More APAC Real Estate Headlines

In today’s review of real estate news from around the region, City Developments Ltd launches a $2 billion perpetual securities programme with UOB as arranger, Ares Management expands its Japan logistics portfolio under the Marq brand with three newly acquired... Read More>> The post CDL Launches $1.6B Perpetual Securities Programme and More APAC Real Estate Headlines appeared

Newsletter

Don't miss

AIONOS Highlights Enterprise AI Vision for APAC at GITEX AI ASIA 2026

SINGAPORE, Apr 10, 2026 - (ACN Newswire) - AIONOS, a Singapore-based enterprise AI company backed by InterGlobe Enterprises and Assago Group, is making a strong presence at GITEX AI ASIA 2026, taking place from 9 to 10 April at Marina Bay Sands, Singapore. The company’s participation reflects its increasing investment in the Asia Pacific region

‘I Was Immediately Admitted’ – Junior Pope’s Wife Recounts Husband’s Devastating Death

The wife of late Nollywood actor, JohnPaul Odonwodo, popularly known as Junior Pope , Jennifer Odonwodo, has recounted the devastating moment she received news of his death. Naija News reports that Jennifer, in a post via her Instagram page on Friday, described the incident as “the most devastating call” of her life and had assumed

NASA prepares for Artemis 2 return

WASHINGTON — The Artemis 2 mission is set for a final, fiery test when the spacecraft reenters April 10 ahead of a splashdown off the California coast. Artemis 2 will wrap up a mission lasting a little more than nine days with a tightly choreographed sequence of events in the mission’s final hour. It starts

CDL Launches $1.6B Perpetual Securities Programme and More APAC Real Estate Headlines

In today’s review of real estate news from around the region, City Developments Ltd launches a $2 billion perpetual securities programme with UOB as arranger, Ares Management expands its Japan logistics portfolio under the Marq brand with three newly acquired... Read More>> The post CDL Launches $1.6B Perpetual Securities Programme and More APAC Real Estate Headlines appeared

India becomes third largest country for solar PV capacity

The MNRE said it is still aiming to achieve Prime Minister Modi’s pledge to reach 500GW of renewable energy and nuclear capacity on India’s grid by 2030. Total solar capacity has increased by 53.28 times since 2014, the MNRE said, rising from 2.82GW in March 2014 to over 150GW in March 2026. It said that

Tesla’s Business Has Become Much More Diversified in Just the Past Five Years. Does That Make Its Stock a Better Buy Today?

Key Points Tesla's energy generation and storage segment generated 27% revenue growth last year. The company's non-automotive segments were able to help offset a double-digit decline in auto revenue in 2025. These 10 stocks could mint the next wave of millionaires › Tesla (NASDAQ: TSLA) is known for its electric vehicles (EVs), and while they

WD sees sustainability as key business driver in an ‘AI economy’

Hard drive company WD promoted long-term operations and sustainability executive Jackie Jung to become its first chief sustainability officer in February, as it steps up sales to companies building AI data centers. Her vision: Turn sustainability into a “brand” for WD, a strategy that reduces risk for the $6 billion company (formerly known as Western

5 Business Ideas Worth Starting in 2026

If there is one thing Nigerians understand well, it is how to spot opportunity inside hardship. In 2026, that mindset will matter more than ever. The economy is tough, competition is rising, and many people are looking for smarter ways to earn, build, and survive. But even in a difficult environment, some businesses still stand