Security-X
Forum Security-X => News => Discussion démarrée par: igor51 le mai 25, 2012, 08:00:35
-
Yahoo Includes Private Key in Source File For Axis Chrome Extension
<p>Yahoo on Wednesday launched a new browser called Axis and researchers immediately discovered that the company had mistakenly included its private signing key in the source file, a serious error that would allow an attacker to create a malicious, signed extension for a browser that the browser will then treat as authentic.</p><p><a href="http://m.threatpost.com/en_us/blogs/yahoo-includes-private-key-source-file-axis-chrome-extension-052412" target="_blank">read more</a></p>
Source: Yahoo Includes Private Key in Source File For Axis Chrome Extension (http://m.threatpost.com/en_us/blogs/yahoo-includes-private-key-source-file-axis-chrome-extension-052412)