A new vulnerability in Chrome Autofill system, Opera and Safari. Learn how to protect yourself
News Browsers / / December 19, 2019
If you use the AutoComplete feature in Chrome, Opera or Safari, then beware: attackers can steal your payment data. How to protect yourself from it - says Layfhaker.
All modern browsers have autocomplete forms. You just once stored in your browser the address, e-mail, name, payment details, and you can then paste them into any form with just one mouse click. It's really good, and many people use this feature.
Vildzhami Kuosmanen (Viljami Kuosmanen), the Finnish web developer and hacker, recently I discovered vulnerability in this function. The attacker may create a special page that mimics some useful service that will tempt your credit card details.
To do this on the registration page create fake service creates a special form with hidden fields. You see only the fields to enter your name and email address, click on the AutoComplete button, and without knowing it, hackers are sending your payment data.
To avoid falling into this trap, better yet refuse to use AutoFill. This can be done as follows:
- IN Chrome click on the button with three dots in the upper right corner. Select "Settings", and then in the bottom of the page, click on the "Show advanced settings." Look for the section "Passwords and forms" and uncheck the option "Enable Autofill forms with a single click."
- IN Safari select "Settings» → «AutoFill" and uncheck the boxes next to all the data.
- IN Opera open the browser options, click the "Security" tab, search for "Autofill." Uncheck the box next to the option "Enable Autofill Forms pages."
Mozilla Firefox is protected against this vulnerability, as its auto-complete system is not yet able to work with forms that contain a lot of fields.
Make these changes right now, so as not to fall for the bait scams.