Sunday, July 27, 2025
  • Hype
  • Murai
  • Lipstiq
  • Miss Murai
  • Varnam
  • Moviedash
  • Autofreaks
Lowyat.NET
  • News
    • Lifestyle
    • Computing
    • Hardware
    • Internet
    • Rumours & Leaks
    • Software
  • Forums
    • Kopitiam
    • Tradezone
    • Property Talk
    • Finance & Business
    • Fast and Furious
  • Gaming
    • PC Gaming
    • Console
    • Esports
  • Mobile
    • Apps
    • OS
    • Tablets
    • Phones
    • Telco
      • Celcom
      • DiGi
      • Maxis
      • Tune Talk
      • U Mobile
      • Buzzme
  • Pricelists
    • Compu-zoneUpdated
    • ViewnetUpdated
    • Sri ComputersUpdated
    • StartecUpdated
  • More
    • Automotive Tech
    • Drone
    • Enterprise
    • Entertainment
    • Fashion
    • E-Hailing
    • Wearables
No Result
View All Result
Lowyat.NET
  • News
    • Lifestyle
    • Computing
    • Hardware
    • Internet
    • Rumours & Leaks
    • Software
  • Forums
    • Kopitiam
    • Tradezone
    • Property Talk
    • Finance & Business
    • Fast and Furious
  • Gaming
    • PC Gaming
    • Console
    • Esports
  • Mobile
    • Apps
    • OS
    • Tablets
    • Phones
    • Telco
      • Celcom
      • DiGi
      • Maxis
      • Tune Talk
      • U Mobile
      • Buzzme
  • Pricelists
    • Compu-zoneUpdated
    • ViewnetUpdated
    • Sri ComputersUpdated
    • StartecUpdated
  • More
    • Automotive Tech
    • Drone
    • Enterprise
    • Entertainment
    • Fashion
    • E-Hailing
    • Wearables
No Result
View All Result
Lowyat.NET
No Result
View All Result
Home News Internet

AVG’s Web Tuneup Plugin Turned Out To Be A Huge Security Flaw In Chrome

by Khalis Onn
December 31, 2015
13
SHARES
Share on FacebookShare on Twitter

avg-web-tuneup_2

AVG’s Web Tuneup, a plugin that is supposed to protect users from online threats, has turned out to be a major security flaw that exposes users’ browsing history and personal data to hackers. The plugin works by sending addresses of sites visited by users to AVG’s servers in order to check them against AVG’s database of malicious sites. However, Google’s security team noted that the plugin was overriding safety features built into the search firm’s Chrome browser.

The team also found that hackers could hijack the data by using a technique known as cross-site scripting (XXS). This method allows attackers to inject malicious scripts into trusted web pages viewed by other users. XXS is also used to bypass access controls such as same-origin policy.

Google security researcher, Tavis Ormandy, highlighted that Web Tuneup was “force-installed” by AVG antivirus into Chrome, and as a result, Google confirmed that nine million Chrome users were affected.

2015-12-30-640x324

Tavis wrote to AVG regarding the issue saying: “Apologies for my harsh tone, but I’m really not thrilled about this trash being installed for Chrome users.

My concern is that your security software is disabling web security for nine million Chrome users, apparently so that you can hijack search settings and the new tab page. I hope the severity of this issue is clear to you, fixing it should be your highest priority.”

Although AVG has addressed the problem, Tavis’ message shows that its attempt did not work after all. AVG later stated that: “We thank the Google Security Research Team for making us aware of the vulnerability with the Web TuneUp optional Chrome extension.”

ALSO READ:  Google NotebookLM App Now Available For Android And iOS

avg-antivirus-free-22-690x535

The company has since updated the plugin to fix the vulnerability. The fix was done before Christmas and users should automatically receive the updated version of Web Tuneup. Additionally, the plugin will no longer be force-installed for new users of AVG antivirus.

(Source: BBC via HardwareZone)

Filed Under AntivirusAVGGoogleGoogle ChromeHack
Updated 1:18 pm, Thu, 31 December 15
https://lowy.at/TCMA3
Share5Tweet3SendShare

Follow us on Instagram, Facebook, Twitter or Telegram for more updates and breaking news. 

No Result
View All Result

TRENDING THIS WEEK

  1. 1
    Apps

    Public Bank’s PB engage MY App No Longer Accessible From 15 August 2025

  2. 2
    News

    Intel To Consolidate Chip Assembly And Test Operations In Malaysia

  3. 3
    Hardware

    Hypershell Exoskeleton Now Available In Malaysia From RM4,999

  4. 4
    Mobile Phones

    HONOR Introduces “Worry-Free” Service For Magic V5

  5. 5
    Automotive

    Proton Launches New Facelifted X50; Staring Price RM89,900

NETWORK

  • Hype
  • Murai
  • Lipstiq
  • Miss Murai
  • Varnam
  • Moviedash
  • Autofreaks

ABOUT

  • Advertise
  • Careers
  • Privacy Statement
  • Contact Us
  • Editorial Policy
  • Terms & Conditions

©2025 VIJANDREN RAMADASS. ALL RIGHTS RESERVED.

No Result
View All Result
  • News
    • Lifestyle
    • Computing
    • Hardware
    • Internet
    • Rumours & Leaks
    • Software
  • Forums
    • Kopitiam
    • Tradezone
    • Property Talk
    • Finance & Business
    • Fast and Furious
  • Gaming
    • PC Gaming
    • Console
    • Esports
  • Mobile
    • Apps
    • OS
    • Tablets
    • Phones
    • Telco
      • Celcom
      • DiGi
      • Maxis
      • Tune Talk
      • U Mobile
      • Buzzme
  • Pricelists
    • Compu-zone
    • Viewnet
    • Sri Computers
    • Startec
  • More
    • Automotive Tech
    • Drone
    • Enterprise
    • Entertainment
    • Fashion
    • E-Hailing
    • Wearables

©2025 VIJANDREN RAMADASS. ALL RIGHTS RESERVED.

No Result
View All Result
  • News
    • Lifestyle
    • Computing
    • Hardware
    • Internet
    • Rumours & Leaks
    • Software
  • Forums
    • Kopitiam
    • Tradezone
    • Property Talk
    • Finance & Business
    • Fast and Furious
  • Gaming
    • PC Gaming
    • Console
    • Esports
  • Mobile
    • Apps
    • OS
    • Tablets
    • Phones
    • Telco
      • Celcom
      • DiGi
      • Maxis
      • Tune Talk
      • U Mobile
      • Buzzme
  • Pricelists
    • Compu-zone
    • Viewnet
    • Sri Computers
    • Startec
  • More
    • Automotive Tech
    • Drone
    • Enterprise
    • Entertainment
    • Fashion
    • E-Hailing
    • Wearables

©2025 VIJANDREN RAMADASS. ALL RIGHTS RESERVED.