The vulnerability was submitted by researchers from the Avast Threat Intelligence team, who had already discovered that the vulnerability was being exploited by Israeli spyware developers. The spyware developer, Candiru, helps its clients launch attacks against users in Lebanon, Turkey, Yemen, and Palestine.

Affected browsers include but are not limited to Google Chrome, in fact, any browser based on the Chromium kernel will exist this vulnerability. In one case, attackers compromised a Lebanese news organization to enable JavaScript snippets used in XSS cross-site scripting attacks on its website. When the victim visits the website, the attacker will call 50 data points to analyze it, and if it is determined to be the target user, it will use the vulnerability to establish a data exchange. “The collected information includes the victim’s language, timezone, screen information, device type, browser plugins, referrer, device memory, cookie functionality, and more,” explains Avast’s report.
Support Our Threat Intelligence
If you find our CVE report and cybersecurity news helpful, consider supporting our work.