Close Menu
Technology Mag

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Vimeo to be acquired by Bending Spoons for $1.38 billion

    September 10, 2025

    The ‘Final Fantasy Tactics’ Refresh Gives Its Class-War Story New Relevance

    September 10, 2025

    How the new AirPods Pro compare to the rest of Apple’s AirPods lineup

    September 10, 2025
    Facebook X (Twitter) Instagram
    Subscribe
    Technology Mag
    Facebook X (Twitter) Instagram YouTube
    • Home
    • News
    • Business
    • Games
    • Gear
    • Reviews
    • Science
    • Security
    • Trending
    • Press Release
    Technology Mag
    Home » Researcher reveals ‘catastrophic’ security flaw in the Arc browser
    News

    Researcher reveals ‘catastrophic’ security flaw in the Arc browser

    News RoomBy News RoomSeptember 20, 20241 Min Read
    Facebook Twitter Pinterest LinkedIn Reddit WhatsApp Email

    Arc has a feature called Boosts that allows you to customize any website with custom CSS and Javascript. Since running arbitrary Javascript on websites has potential security concerns, we opted not to make Boosts with custom Javascript shareable across members, but we still synced them to our server so that your own Boosts are available across devices.

    We use Firebase as the backend for certain Arc features (more on this below), and use it to persist Boosts for both sharing and syncing across devices. Unfortunately our Firebase ACLs (Access Control Lists, the way Firebase secures endpoints) were misconfigured, which allowed users Firebase requests to change the creatorID of a Boost after it had been created. This allowed any Boost to be assigned to any user (provided you had their userID), and thus activate it for them, leading to custom CSS or JS running on the website the boost was active on.

    Share. Facebook Twitter Pinterest LinkedIn WhatsApp Reddit Email
    Previous ArticleHow to Switch iPhones Without Losing a Thing
    Next Article The best Garmin watches for training and everyday life

    Related Posts

    Vimeo to be acquired by Bending Spoons for $1.38 billion

    September 10, 2025

    How the new AirPods Pro compare to the rest of Apple’s AirPods lineup

    September 10, 2025

    Hands-on: Nvidia’s GeForce Now RTX 5080 is better and worse than I hoped

    September 10, 2025

    Nvidia’s latest GeForce driver is ready for Borderlands 4 and RTX Remix mods

    September 10, 2025

    Apple’s misunderstood crossbody iPhone strap might be the best I’ve seen

    September 10, 2025

    Zillow’s new AI staging feature is impressively unimpressive

    September 10, 2025
    Our Picks

    The ‘Final Fantasy Tactics’ Refresh Gives Its Class-War Story New Relevance

    September 10, 2025

    How the new AirPods Pro compare to the rest of Apple’s AirPods lineup

    September 10, 2025

    Massive Leak Shows How a Chinese Company Is Exporting the Great Firewall to the World

    September 10, 2025

    The United Arab Emirates Releases a Tiny But Powerful AI Model

    September 10, 2025
    • Facebook
    • Twitter
    • Pinterest
    • Instagram
    • YouTube
    • Vimeo
    Don't Miss
    News

    Hands-on: Nvidia’s GeForce Now RTX 5080 is better and worse than I hoped

    By News RoomSeptember 10, 2025

    Today, Nvidia is soft-launching its latest gaming GPUs in the cloud — upgrading its $20-a-month…

    Nvidia’s latest GeForce driver is ready for Borderlands 4 and RTX Remix mods

    September 10, 2025

    Apple’s misunderstood crossbody iPhone strap might be the best I’ve seen

    September 10, 2025

    Real Estate Speculators Are Swooping In to Buy Disaster-Hit Homes

    September 10, 2025
    Facebook X (Twitter) Instagram Pinterest
    • Privacy Policy
    • Terms of use
    • Advertise
    • Contact
    © 2025 Technology Mag. All Rights Reserved.

    Type above and press Enter to search. Press Esc to cancel.