Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    10 Free Crypto Cloud Mining Platforms in 2025

    June 13, 2025

    Israel strikes Iran, cryptocurrency market rolls

    June 13, 2025

    Why the brand invests in two-tier music festival sponsorship

    June 12, 2025
    Facebook X (Twitter) Instagram
    Facebook X (Twitter) Instagram
    Comic Vibe
    Subscribe
    • Home
    • Comics
    • Gaming
    • Movies
    • TV
    • Anime
    • Toys
    • Cosplay
    • Tech
    • NFT
    • Metaverse
    • Events
    Comic Vibe
    Home»Tech»Researchers reveal “catastrophic” security vulnerability in Arc Browser
    Tech

    Researchers reveal “catastrophic” security vulnerability in Arc Browser

    Comic VibeBy Comic VibeSeptember 20, 2024No Comments1 Min Read
    Facebook Twitter Pinterest LinkedIn Tumblr Email
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Arc has a feature called Boosts that allows you to customize any website using custom CSS and Javascript. Due to the potential security issues of executing arbitrary Javascript on the site, we choose not to allow Boost with custom Javascript to be shared among members, but we still sync them to our servers so that your own Boost can Use across devices.

    We use Firebase as the backend for some Arc features (more on that below) and use it to consistently enhance cross-device sharing and synchronization. Unfortunately, our Firebase ACL (Access Control List, the way Firebase protects endpoints) was misconfigured, causing users Firebase to request a change to their CreatorID after building Boost. This allows any Boost to be assigned to any user (provided you have their user ID), thereby activating it for them, causing custom CSS or JS to run on the website where that boost is active.

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Comic Vibe

    Related Posts

    The ending of “Folie à Deux” comes from an abandoned idea of ​​the first film

    October 7, 2024

    Apple’s next MacBook Pro may have leaked in Russia

    October 7, 2024

    The best early October Prime Day MacBook deals: Amazon shopping at record lows

    October 7, 2024

    Samsung launches Neo QLED 4K smart TV with discounts of up to $1,755 to compete with Amazon Prime Day

    October 7, 2024
    Add A Comment

    Comments are closed.

    Our Picks
    • Facebook
    • Twitter
    • Pinterest
    • Instagram
    • YouTube
    • Vimeo
    Don't Miss
    NFT

    10 Free Crypto Cloud Mining Platforms in 2025

    By Comic VibeJune 13, 20250

    In a digital age dominated by passive income sources, crypto mining has become a favorite…

    Israel strikes Iran, cryptocurrency market rolls

    June 13, 2025

    Why the brand invests in two-tier music festival sponsorship

    June 12, 2025

    Blockdag’s NBA trading, binary price recovery and hyperliquidity buzz

    June 12, 2025
    Editors Picks
    Top Reviews
    Our Picks

    10 Free Crypto Cloud Mining Platforms in 2025

    June 13, 2025

    Israel strikes Iran, cryptocurrency market rolls

    June 13, 2025

    Why the brand invests in two-tier music festival sponsorship

    June 12, 2025
    Legal Pages
    • About Us
    • Contact Us
    • Disclaimer
    • Privacy Policy
    Our Picks

    Type above and press Enter to search. Press Esc to cancel.