
My browser got hacked and it cost me $2,000
Source: YouTube · Theo - t3․gg · published Sep 27, 2024 · 21:42
A critical vulnerability in the Arc browser allowed attackers to execute arbitrary JavaScript on users' browsers with just their user ID 0:35-0:41.
Key Takeaways:
• The vulnerability existed in Arc's "boosts" feature, which allows users to customize websites with custom CSS and JavaScript 5:05-5:16
• Security researcher Eva discovered that the Creator ID field in Firebase was not properly restricted, allowing her to create malicious boosts and assign them to other users 13:20-13:27
• Arc initially offered only $2,000 bounty for this critical vulnerability, which was criticized as insufficient before increasing it to $20,000 15:11-15:18
• Arc confirmed no users were actually affected by this vulnerability, and they have since patched it and are moving off Firebase for new features 17:33-17:37
Arc has taken steps to address the vulnerability by improving their security practices, though this incident highlights the risks of improper Firebase security configurations 18:44-18:47.
Sources:
- 0:35-0:41 Explanation of the vulnerability allowing arbitrary JavaScript execution
- 5:05-5:16 Description of Arc boosts feature and functionality
- 13:20-13:27 Technical details of the Creator ID field vulnerability
- 15:11-15:18 Discussion about the bounty controversy and increase
- 17:33-17:37 Arc's confirmation that no users were affected
- 18:44-18:47(https://www.youtube.com/watch?v=d0PyfY
Generate CPE Credits
Generate a professional CPE document from this video's transcript.
Estimated credit: 0.5 CPE hours
Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.
Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.
Free account. One generation at a time, with a daily limit.
CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.
Transcript Preview
First 800 characters of the transcript
people often ask me what browser I'm using because they see it and it looks really different I've even had people assume that my stream had a crazy setup that wasn't even using a traditional browser but I am I'm using Arc it was not my favorite thing initially but over time it ended up becoming a browser I quite liked it's Chrome based but its workflow is very different they've built a ton of cool features on top of it and a bunch of features that I'm not that interested in but some of those features might touch things they shouldn't and some hacker specifically friend of the stream Eva managed to do some things she should not have been able to we need to talk about those things because those things include the ability to run whatever arbitary JavaScript you want to on my browser and all y…