Skip to content

Airvers Tech News

Focus on science and technology.

Primary Menu
  • Home
  • Technology
  • Science
  • Movie
  • Music
  • Game
  • Comic
  • Anecdote
  • Software
  • Home
  • Technology
  • Newly Discovered Browser Vulnerability Allows Overwriting Clipboard Content Could Seriously Affect Cryptocurrency Security
  • Technology

Newly Discovered Browser Vulnerability Allows Overwriting Clipboard Content Could Seriously Affect Cryptocurrency Security

Andrew 09/03/2022 2 min read

Google developer Jeff Johnson explained how the vulnerability was triggered, several ways by granting a page permission to overwrite the contents of the clipboard. Once permission is granted, users can influence by actively triggering a cut or copy action, clicking a link in a page, or even taking the simple action of scrolling up or down on the page in question.

The difference between the browsers is that Firefox and Safari users must actively copy content to the clipboard using Control+C or ⌘-C, while Chrome users can be affected by viewing a malicious page for no more than a fraction of a second.

Johnson’s blog post cites the video example of Šime, a content creator that specializes in web developers. Šime’s demo revealed how quickly Chrome browser users are affected, triggering the vulnerability whenever they switch between active browser tabs. Regardless of how long or what type of interaction the user has had, the malicious website will immediately replace any clipboard content with what the threat actor decides to offer.

Johnson’s blog provides technical details describing how a page can gain permission to write to the system clipboard. One way is to use a now deprecated command, document.execCommand.

Another way is to take advantage of the recent navigator.clipboard.writetext API, which has the ability to write any text to the clipboard without additional manipulation. A demo showing how two approaches to the same vulnerability work.

While this vulnerability may sound innocuous on the surface, users should remain vigilant that malicious actors could exploit content swapping to take advantage of unsuspecting victims. For example, a fraudulent website can replace a previously copied URL with another fraudulent URL, unknowingly directing users to other websites designed to gain information and compromise security.

The vulnerability also provides threat actors the ability to save a copied cryptocurrency wallet address on the clipboard, replacing it with the address of another wallet controlled by a malicious third party. Once a transaction occurs and funds are sent to fraudulent wallets, victimized users often have little ability to trace and recover their funds.

Google is aware of this vulnerability and is expected to release a patch in the near future. Until then, users should exercise caution, avoid opening web pages with clipboard-based copies, and verify the output of their copies before proceeding with any activity that could jeopardize their personal or financial security.

Related

Continue Reading

Previous: Security researchers successfully hijack Windows 11’s Power Automate tool
Next: Suspected Google Pixel 7 Pro appears in unboxing video ahead of launch

Read More

“League of Legends” S12 semi-finals are all confirmed: LPL only has JDG left to open the semi-finals on October 30
1 min read
  • Technology

“League of Legends” S12 semi-finals are all confirmed: LPL only has JDG left to open the semi-finals on October 30

10/23/2022
Tesla Model 3, Y slashed prices! Car owners collectively come to their homes to defend their rights, and some sales have been hit
1 min read
  • Technology

Tesla Model 3, Y slashed prices! Car owners collectively come to their homes to defend their rights, and some sales have been hit

10/23/2022
New Zealand’s plan to levy burp fees for cattle and sheep is blocked: farmers drive tractors to the streets to protest
1 min read
  • Technology

New Zealand’s plan to levy burp fees for cattle and sheep is blocked: farmers drive tractors to the streets to protest

10/23/2022

Archives

  • October 2022
  • September 2022
  • August 2022
  • July 2022
  • June 2022
  • May 2022
  • April 2022
  • March 2022
  • February 2022
  • January 2022
  • December 2021
  • November 2021
  • October 2021
  • “League of Legends” S12 semi-finals are all confirmed: LPL only has JDG left to open the semi-finals on October 3010/23/2022
  • Tesla Model 3, Y slashed prices! Car owners collectively come to their homes to defend their rights, and some sales have been hit10/23/2022
  • The world’s first phase 3 psychedelic clinical trial is about to begin10/23/2022
  • New Zealand’s plan to levy burp fees for cattle and sheep is blocked: farmers drive tractors to the streets to protest10/23/2022
  • Study: Newly discovered protein could help save lives10/23/2022

Newest

“League of Legends” S12 semi-finals are all confirmed: LPL only has JDG left to open the semi-finals on October 30
1 min read
  • Technology

“League of Legends” S12 semi-finals are all confirmed: LPL only has JDG left to open the semi-finals on October 30

10/23/2022
Tesla Model 3, Y slashed prices! Car owners collectively come to their homes to defend their rights, and some sales have been hit
1 min read
  • Technology

Tesla Model 3, Y slashed prices! Car owners collectively come to their homes to defend their rights, and some sales have been hit

10/23/2022
The world’s first phase 3 psychedelic clinical trial is about to begin
4 min read
  • Science

The world’s first phase 3 psychedelic clinical trial is about to begin

10/23/2022
New Zealand’s plan to levy burp fees for cattle and sheep is blocked: farmers drive tractors to the streets to protest
1 min read
  • Technology

New Zealand’s plan to levy burp fees for cattle and sheep is blocked: farmers drive tractors to the streets to protest

10/23/2022
  • Home
  • Technology
  • Science
  • Movie
  • Music
  • Game
  • Comic
  • Anecdote
  • Software
Copyright © All rights reserved.