// NEWS // Edge Lets Facebook Execute Flash Code Without Your Permission!

in #news7 years ago

The default browser in Windows 10 contains a whitelist that is hard to justify and that exposes users to uncontrollable attacks.

Microsoft-Edge-Probleme-und-Loesungen-658x370-e59f03f7e201928b.jpg
Source

The Windows 10 browser whitelist can execute Flash code without the user’s permission.
Until February, this list contained 58 entries for as many sites, including sub-domains of Microsoft, Deezer, Yahoo or QQ (a Chinese social network). The most surprising - and which raises questions about the thinking that presided over the composition of this list - is the presence of a Spanish hairdresser website

The default Flash whitelist in the Edge really surprised me. So many sites for which I'm completely baffled as to why they're there. Like a site of a hairdresser in Spain ?! I wonder how the list was formed. And if MSRC knew about it. - Ivan Fratric (@ifsecure) February 19, 2019

What does that entail

These different sites could bypass the click-to-play policy which permits that Flash content on a website can only be executed if the user explicitly allows it.

Ivan Fratric, Google Project Zero security researcher, who discovered this whitelist and reported the bug last November believes this poses a big security problem, as some of these pre-authorized sites are known to suffer from XSS vulnerabilities. This could lead to the execution of dangerous Flash code and the PC using Edge contamination.

Now Microsoft has narrowed the whitelist to just 2 areas of Facebook: the main site and its subdomain apps.facebook.com. The security researcher wonders about the need to maintain a dangerous free-pass for Facebook. (I think it is to allow the execution of many Flash games present on the social platform, but how to be sure?..)

The context

Flash technology is expected to retire partially or semi-definitively in 2020 because it is widely criticized for safety. It is a real nest of breaches which should be avoided as much as possible on a daily basis. Browsers as Brave tend to block the default execution.

DQmdpsoEfLe5nRg4Q1oKWHNjLdMnAucCYfRou1yF5Yiwrzs.png

DQmNuF3L71zzxAyJB7Lk37yBqjBRo2uafTAudFDLzsoRV5L.gif

Coin Marketplace

STEEM 0.04
TRX 0.32
JST 0.077
BTC 63768.03
ETH 1675.48
USDT 1.00
SBD 0.41