Internet Explorer bug leaks whatever you type in the address bar

Ars Technica – by Dan Goodin

There’s a bug in the latest version of Internet Explorer that leaks the addresses, search terms, or any other text typed into the address bar.

The bug allows any currently visited website to view any text entered into the address bar as soon as the user hits enter. The technique can expose sensitive information a user didn’t intend to be viewed by remote websites, including the Web address the user is about to visit. The hack can also expose search queries, since IE allows them to be typed into the address bar and then retrieved from Bing or other search services.

The flaw was disclosed Tuesday by security researcher Manuel Caballero. This proof-of-concept site shows the exploit works as described on the latest version of IE.

The proof-of-concept makes it transparent that the attacking website is viewing the entered text. The hack, however can easily be modified to make the information theft completely stealthy. Either way, this weakness may allow malicious sites to view information the user presumed was private. People should strongly consider using Google Chrome, Microsoft Edge, or another non-IE browser. Microsoft officials didn’t immediately have a comment for this post.

https://arstechnica.com/information-technology/2017/09/bug-in-fully-patched-internet-explorer-leaks-text-in-address-bar/

One thought on “Internet Explorer bug leaks whatever you type in the address bar

Join the Conversation

Your email address will not be published. Required fields are marked *


*