Chrome 76 ichavhara incognito kubhurawuza yekuona loophole

Google yakashuma nezve shanduko kumaitiro eincognito modhi mukuburitswa kweChrome 76, yakarongerwa Chikunguru 30. Kunyanya, mukana wekushandisa loophole mukushandiswa kweFileSystem API, iyo inobvumira munhu kuti aone kubva kune web application kana mushandisi ari kushandisa incognito mode, ichavharwa.

Chinokosha cheiyo nzira ndeyokuti kare, kana uchishanda mu incognito mode, bhurawuza rakavhara kupinda kune FileSystem API kudzivirira data kubva pakugadzirisa pakati pezvikamu, i.e. kubva kuJavaScript, zvaive zvichibvira kutarisa kukwanisa kuchengetedza data kuburikidza neFilesSystem API uye, kana kukanganisa, kutonga basa re incognito mode. Mune ramangwana rekuburitswa kweChrome, kupinda kuFileSystem API hakuzovharwi, asi zvirimo zvichacheneswa mushure mekupera kwechikamu.

Iyi nzira yaishandiswa zvakanyanya nemamwe masayiti anoshanda pamuenzaniso wekupa mukana wakazara kuburikidza nekubhadhara kunyoreswa (paywall), asi vasati vadzikamisa kugona kuona zvizere zvinyorwa zvezvinyorwa, vanopa vashandisi vatsva demo yakazara yenguva kwenguva yakati. Saizvozvo, nzira iri nyore yekuwana zvakabhadharwa zvemukati masisitimu akadaro ndeye kushandisa incognito mode. Vaparidzi havasi kugutsikana nemaitiro aya, saka vachangobva kushandisa zvine chekuita nazvo
FileSystem API inzira yekuvharisa kupinda kune saiti kana incognito modhi yakagoneswa uye ichikukurudzira kudzima iyi modhi kuti uenderere mberi nekubhurawuza.

Source: opennet.ru

Voeg