Close Menu
Technology Mag

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot
    One of Grammarly’s ‘experts’ is suing the company over its identity-stealing AI feature

    One of Grammarly’s ‘experts’ is suing the company over its identity-stealing AI feature

    March 11, 2026
    iPhone Fold rumor: iPad-like multitasking, but no iPad apps and no Face ID

    iPhone Fold rumor: iPad-like multitasking, but no iPad apps and no Face ID

    March 11, 2026
    You can’t replace the battery in Lego’s Smart Bricks — and many of its sensors aren’t available yet

    You can’t replace the battery in Lego’s Smart Bricks — and many of its sensors aren’t available yet

    March 11, 2026
    Facebook X (Twitter) Instagram
    Subscribe
    Technology Mag
    Facebook X (Twitter) Instagram YouTube
    • Home
    • News
    • Business
    • Games
    • Gear
    • Reviews
    • Science
    • Security
    • Trending
    • Press Release
    Technology Mag
    Home » Researcher reveals ‘catastrophic’ security flaw in the Arc browser
    News

    Researcher reveals ‘catastrophic’ security flaw in the Arc browser

    News RoomBy News RoomSeptember 20, 20241 Min Read
    Facebook Twitter Pinterest LinkedIn Reddit WhatsApp Email
    Researcher reveals ‘catastrophic’ security flaw in the Arc browser

    Arc has a feature called Boosts that allows you to customize any website with custom CSS and Javascript. Since running arbitrary Javascript on websites has potential security concerns, we opted not to make Boosts with custom Javascript shareable across members, but we still synced them to our server so that your own Boosts are available across devices.

    We use Firebase as the backend for certain Arc features (more on this below), and use it to persist Boosts for both sharing and syncing across devices. Unfortunately our Firebase ACLs (Access Control Lists, the way Firebase secures endpoints) were misconfigured, which allowed users Firebase requests to change the creatorID of a Boost after it had been created. This allowed any Boost to be assigned to any user (provided you had their userID), and thus activate it for them, leading to custom CSS or JS running on the website the boost was active on.

    Share. Facebook Twitter Pinterest LinkedIn WhatsApp Reddit Email
    Previous ArticleHow to Switch iPhones Without Losing a Thing
    Next Article The best Garmin watches for training and everyday life

    Related Posts

    One of Grammarly’s ‘experts’ is suing the company over its identity-stealing AI feature

    One of Grammarly’s ‘experts’ is suing the company over its identity-stealing AI feature

    March 11, 2026
    iPhone Fold rumor: iPad-like multitasking, but no iPad apps and no Face ID

    iPhone Fold rumor: iPad-like multitasking, but no iPad apps and no Face ID

    March 11, 2026
    You can’t replace the battery in Lego’s Smart Bricks — and many of its sensors aren’t available yet

    You can’t replace the battery in Lego’s Smart Bricks — and many of its sensors aren’t available yet

    March 11, 2026
    Microsoft’s next Xbox, Project Helix, won’t reach alpha until 2027

    Microsoft’s next Xbox, Project Helix, won’t reach alpha until 2027

    March 11, 2026
    Grammarly says it will stop using AI to clone experts without permission

    Grammarly says it will stop using AI to clone experts without permission

    March 11, 2026
    Microsoft’s ‘Xbox mode’ is coming to every Windows 11 PC

    Microsoft’s ‘Xbox mode’ is coming to every Windows 11 PC

    March 11, 2026
    Our Picks
    iPhone Fold rumor: iPad-like multitasking, but no iPad apps and no Face ID

    iPhone Fold rumor: iPad-like multitasking, but no iPad apps and no Face ID

    March 11, 2026
    You can’t replace the battery in Lego’s Smart Bricks — and many of its sensors aren’t available yet

    You can’t replace the battery in Lego’s Smart Bricks — and many of its sensors aren’t available yet

    March 11, 2026
    Microsoft’s next Xbox, Project Helix, won’t reach alpha until 2027

    Microsoft’s next Xbox, Project Helix, won’t reach alpha until 2027

    March 11, 2026
    Grammarly says it will stop using AI to clone experts without permission

    Grammarly says it will stop using AI to clone experts without permission

    March 11, 2026
    • Facebook
    • Twitter
    • Pinterest
    • Instagram
    • YouTube
    • Vimeo
    Don't Miss
    Microsoft’s ‘Xbox mode’ is coming to every Windows 11 PC News

    Microsoft’s ‘Xbox mode’ is coming to every Windows 11 PC

    By News RoomMarch 11, 2026

    Microsoft seems more determined than ever to combine Xbox and Windows — to the point…

    OpenAI’s Sora video generator is reportedly coming to ChatGPT

    OpenAI’s Sora video generator is reportedly coming to ChatGPT

    March 11, 2026
    500 Internal Server Error | The Verge

    500 Internal Server Error | The Verge

    March 11, 2026
    Canva’s new editing tool adds layers to AI-generated designs

    Canva’s new editing tool adds layers to AI-generated designs

    March 11, 2026
    Facebook X (Twitter) Instagram Pinterest
    • Privacy Policy
    • Terms of use
    • Advertise
    • Contact
    © 2026 Technology Mag. All Rights Reserved.

    Type above and press Enter to search. Press Esc to cancel.