Massive security flaw in Mac devices threatens browsers

Published August 12th, 2024 - 08:48 GMT
Massive security flaw in Mac devices threatens browsers
Massive security flaw in Mac devices threatens browsers (Shutterstock)

ALBAWABA – A massive new security vulnerability was discovered in Mac devices that threatens popular web browsers. The new flaw, known as 0.0.0.0 Day, is affecting all Chromium-based browsers.

0.0.0.0 Day security vulnerability

Researchers discovered a critical new security vulnerability called 0.0.0.0 Day. The new flaw gives hackers direct access to laptops’ services and is affecting all Chromium-based browsers like Google Chrome, Firefox, Safari, and Edge.

0.0.0.0 Day is not that new

According to Fox News, the new flaw is alarming as it has been present in web browsers for 18 years but was only discovered recently.

0.0.0.0 Day flaw was discovered by Oligo, a security firm, as reported by The Hacker News. 0.0.0.0 Day vulnerability uses the IP address 0.0.0.0, which usually looks harmless, but hackers can use it to obtain users’ access to and control local services on devices.

This new security vulnerability is affecting all Chromium-based browsers like Google Chrome, Firefox, Safari, and Edge.

Avi Lumelsky, AI Security Researcher at Oligo, said: “Oligo security exposed a fundamental flaw in how browsers handle network requests, potentially granting malicious actors access to sensitive services running on local devices.”

0.0.0.0 Day flaw allows bypassing Private Network Access (PNA), which prevents public websites from accessing private networks. Thus, 0.0.0.0 Day allows unauthorized actions on diverse devices.

Web browsers and 0.0.0.0 Day

It is worth noting that affected web browsers include Google Chrome, Edge, Safari, and Firefox on macOS and Linux. Windows users do not have to worry as Microsoft blocks this address on their operating systems.

Apple and Google started blocking access to the IP address 0.0.0.0.

Subscribe

Sign up to our newsletter for exclusive updates and enhanced content