Google Fixes 23-Year-Old Chrome Flaw That Could Leak Your Browser History

Check out our latest products

Added to wishlistRemoved from wishlist 0
Add to compare
[K-Beauty] Rose Vitamin Oil to Foam | Daily Face Wash Oil Based Cleanser | Korean Rose Oil Foaming Face Cleanser | Hydrating Facial Cleanser for Dry Sensitive Skin (3.88 oz)
Added to wishlistRemoved from wishlist 0
Add to compare
$23.99
Added to wishlistRemoved from wishlist 0
Add to compare
100 Pieces Hand Palette makeup artist supplies Single Use Makeup Hand Palette Makeup Mixing Palette Makeup Artist Must Haves Transparent Waterproof Makeup Tape for Women (2.3 x 2.3 Inches)
Added to wishlistRemoved from wishlist 0
Add to compare
Original price was: $5.48.Current price is: $4.48.
18%
Added to wishlistRemoved from wishlist 0
Add to compare
100% Grass Fed Beef Tallow for Skin Care – Face + Body – Whipped Moisturizer – Natural Lotion, 4 FL. oz. (Vanilla Latte)
Added to wishlistRemoved from wishlist 0
Add to compare
Original price was: $39.99.Current price is: $31.99.
20%

If you’ve spent a decent amount of time on the web, you’ve probably noticed that blue links turn purple after you click on them. But you probably didn’t realize that this small detail facilitated a two-decades-old security flaw that could have revealed sensitive details about your browsing history, and which Google has only just patched. 

Explaining the flaw in a recent blog, Google said the browser cookies indicating whether or not you click on a link were what it called “unpartitioned.” This meant that if you clicked a link, it would show as visited on every website displaying that link, even if it was completely unrelated.

Google called this a “core design flaw,” as it potentially leaked information about users’ online activity. “You are browsing on Site A and click a link to go to Site B,” explained Google. “In this scenario, Site B would be added to your visited history. Later, you might visit Site Evil, which creates a link to Site B as well.”

Google highlighted that “Site Evil” could then use this security exploit to learn whether the link was styled as visited, finding out that you’ve visited Site B in the past—leaking information about your browsing history in the process.

The search giant has now corrected the flaw in the latest Chrome update and will store data on what links you click separately, without sharing the info across different websites. The update is set to roll out in the Chrome 136 update and is already available via the Chrome Beta channel.

Recommended by Our Editors

The flaw is older than many Google employees. Security researcher Andrew Clover posted a proof-of-concept attack based on the flaw in 2002, citing a paper by Princeton researchers called “Timing Attacks on Web Privacy.”

It’s not just Google Chrome that was impacted by the problem. A 2009 research paper demonstrated how the bug caused potential security issues in Apple’s Safari, Opera, Internet Explorer, and Mozilla Firefox, The Register reports.

Get Our Best Stories!



Your Daily Dose of Our Top Tech News

Sign up for our What’s New Now newsletter to receive the latest news, best new products, and expert advice from the editors of PCMag.

By clicking Sign Me Up, you confirm you are 16+ and agree to our Terms of Use and Privacy Policy.

Thanks for signing up!

Your subscription has been confirmed. Keep an eye on your inbox!

About Will McCurdy

Contributor

Will McCurdy

I’m a reporter covering weekend news. Before joining PCMag in 2024, I picked up bylines in BBC News, The Guardian, The Times of London, The Daily Beast, Vice, Slate, Fast Company, The Evening Standard, The i, TechRadar, and Decrypt Media.

I’ve been a PC gamer since you had to install games from multiple CD-ROMs by hand. As a reporter, I’m passionate about the intersection of tech and human lives. I’ve covered everything from crypto scandals to the art world, as well as conspiracy theories, UK politics, and Russia and foreign affairs.

Read Will’s full bio

Read the latest from Will McCurdy




Added to wishlistRemoved from wishlist 0
Add to compare
(Pack of 2) Stainless Steel Round Food Ring Sunrise Kitchen Supply (2″ D x 1.5″H)
Added to wishlistRemoved from wishlist 0
Add to compare
$9.35
Added to wishlistRemoved from wishlist 0
Add to compare
(Pack of 2) Sunrise Kitchen Supply Heavy Duty 20 GaugeStainless Steel Deep Fryer Joining Strip/Connector (23″L x 1 1/2″W)
Added to wishlistRemoved from wishlist 0
Add to compare
$54.50

We will be happy to hear your thoughts

Leave a reply

Dust Particle
Logo
Compare items
  • Total (0)
Compare
0
Shopping cart