Google Engineer Finds Serious MS IE8 Flaw

Microsoft is looking into reports of a security issue in Internet Explorer 8. The problem lies with a CSS cross-origin theft issue that has been fixed in other browsers but remains open in IE, said a Google security engineer.

A description of the vulnerability was posted 3 September to the Full Disclosure mailing list by Google Information Security Engineer Chris Evans.

In a proof-of-concept, Evans demonstrated how the bug – a CSS (Cascading Style Sheets) cross-origin theft issue – could be used to force a victim to send a Twitter message.

Internet Explorer Only

“This is purely an IE bug; there is no fault on behalf of Twitter and there is no reasonable workaround,” Evans wrote.

Cross-origin CSS attacks are believed to have first been described back in 2002, according to a recently published paper (PDF file). The other major browser vendors – Apple, Google, Mozilla and Opera Software – have fixed the problem in question in their browsers, but Microsoft has not, Evans wrote on Full Disclosure, even though there is evidence the company has known of the problem “since at least 2008.”

He declined to comment further when asked by eWEEK. But in an August blog post, Evans said IE was the browser most vulnerable to the CSS flaw.

“I have PoCs which will steal your Webmail’s XSRF token, with follow-on loss of account integrity and confidentiality,” he posted at the time. “It’s a nasty attack: Email someone a link and if they click it, they are owned with a pure browser cross-origin bug.”

When asked about the flaw, Microsoft responded that it was looking into the reports and would take appropriate action.

Microsoft Investigates

“Microsoft is investigating new public claims of a possible vulnerability in Internet Explorer,” Jerry Bryant, group manager of response communications for Microsoft Security Response Center, said in a statement 7 September. “We’re currently unaware of any attacks trying to use the claimed vulnerability or of customer impact. Once we’re done investigating, we will take appropriate action to help protect customers. This may include providing a security update through the monthly release process, an out-of-cycle update or additional guidance to help customers protect themselves.”

Earlier versions of IE may be affected as well, according to Evans.

Brian Prince eWEEK USA 2014. Ziff Davis Enterprise Inc. All Rights Reserved

View Comments

  • I knew CSS was powerful, but I didn't know it was THAT powerful...
    One has no idea which browser to use if one wants both functionality and security.

Share
Published by
Brian Prince eWEEK USA 2014. Ziff Davis Enterprise Inc. All Rights Reserved

Recent Posts

Microsoft, OpenAI Sued By More Newspaper Publishers

Eight newspaper publishers in the US allege Microsoft and OpenAI used their millions of their…

27 mins ago

Binance’s Changpeng Zhao Sentenced To Four Months In Prison

US judge sentences Binance founder, Changpeng Zhao, to four months in prison for ignoring money…

4 hours ago

OpenAI Hit By Austrian Complaint Over ChatGPT ‘False Data’

Rights group argues ChatGPT tendency to generate false information on individuals violates GDPR data protection…

1 day ago

EU Designates Apple’s iPad OS As DMA ‘Gatekeeper’

European Commission says Apple's iPadOS is 'gatekeeper' due to large number of businesses 'locked in'…

1 day ago

Beating the Barbarians in the Cloud

As the cloud continues to be an essential asset for all businesses, developing and maintaining…

1 day ago

Austria Conference Calls For Controls On ‘Killer Robots’

Internatinal conference in Vienna calls for controls on AI-powered autonomous weapons to ensure humans remain…

1 day ago