Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    The spotlight disappeared on celebrity speakers

    June 14, 2025

    From Slurpee Street to flavour activation

    June 13, 2025

    How policies in the Trump era reach the conference industry

    June 13, 2025
    Facebook X (Twitter) Instagram
    Facebook X (Twitter) Instagram
    Comic Vibe
    Subscribe
    • Home
    • Comics
    • Gaming
    • Movies
    • TV
    • Anime
    • Toys
    • Cosplay
    • Tech
    • NFT
    • Metaverse
    • Events
    Comic Vibe
    Home»Tech»Researchers reveal “catastrophic” security vulnerability in Arc Browser
    Tech

    Researchers reveal “catastrophic” security vulnerability in Arc Browser

    Comic VibeBy Comic VibeSeptember 20, 2024No Comments1 Min Read
    Facebook Twitter Pinterest LinkedIn Tumblr Email
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Arc has a feature called Boosts that allows you to customize any website using custom CSS and Javascript. Due to the potential security issues of executing arbitrary Javascript on the site, we choose not to allow Boost with custom Javascript to be shared among members, but we still sync them to our servers so that your own Boost can Use across devices.

    We use Firebase as the backend for some Arc features (more on that below) and use it to consistently enhance cross-device sharing and synchronization. Unfortunately, our Firebase ACL (Access Control List, the way Firebase protects endpoints) was misconfigured, causing users Firebase to request a change to their CreatorID after building Boost. This allows any Boost to be assigned to any user (provided you have their user ID), thereby activating it for them, causing custom CSS or JS to run on the website where that boost is active.

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Comic Vibe

    Related Posts

    The ending of “Folie à Deux” comes from an abandoned idea of ​​the first film

    October 7, 2024

    Apple’s next MacBook Pro may have leaked in Russia

    October 7, 2024

    The best early October Prime Day MacBook deals: Amazon shopping at record lows

    October 7, 2024

    Samsung launches Neo QLED 4K smart TV with discounts of up to $1,755 to compete with Amazon Prime Day

    October 7, 2024
    Add A Comment

    Comments are closed.

    Our Picks
    • Facebook
    • Twitter
    • Pinterest
    • Instagram
    • YouTube
    • Vimeo
    Don't Miss
    Events

    The spotlight disappeared on celebrity speakers

    By Comic VibeJune 14, 20250

    Planners increasingly deliver celebrity speakers to support subject matter experts who provide deeper value at…

    From Slurpee Street to flavour activation

    June 13, 2025

    How policies in the Trump era reach the conference industry

    June 13, 2025

    BlockDag boots with smart contract support

    June 13, 2025
    Editors Picks
    Top Reviews
    Our Picks

    The spotlight disappeared on celebrity speakers

    June 14, 2025

    From Slurpee Street to flavour activation

    June 13, 2025

    How policies in the Trump era reach the conference industry

    June 13, 2025
    Legal Pages
    • About Us
    • Contact Us
    • Disclaimer
    • Privacy Policy
    Our Picks

    Type above and press Enter to search. Press Esc to cancel.