Skip to main content

Google wages security war against Microsoft, reveals yet another Windows bug

Microsoft’s recent “call for better coordinated vulnerability disclosure” seems to have hit a brick wall, with Google as quick as ever to expose yet another Windows security glitch. Rated medium for severity, the bug may just be the most troublesome of the three broadcasted this past month.

It’s not (necessarily) that evil hackers will be using the “impersonation check bypass” to wreak havoc on millions of systems running Windows 7 or 8.1, but they could do a lot of harm, and have plenty of time to plan their attacks.

Recommended Videos

Unlike the previous two vulnerabilities made public by Google, this is to be dealt in a matter of weeks… at best. Specifically, on the second Tuesday of February, i.e. the 10th, i.e. the next Patch Tuesday.

As usual, the finder of the malfunction, James Forshaw, followed procedure, posting his discovery on the Google Security Research channel for only authorized eyes to see. That was on October 17, 2014, at which time Microsoft got a note containing the concern and presumed issue’s description.

Of course, the clock began to tick immediately, and Redmond had exactly 90 days to fix things before the post would automatically be derestricted. On October 29, it was confirmed the defect “might constitute a security feature bypass.”

Initially, a universal fix was scheduled to roll out last week, alongside the eight efficient solutions for unrelated “important” and “critical” Windows bugs. But alas, mysterious “compatibility issues” forced a delay for February.

Which brings us to today, and the latest “gotcha” moment in a series of decisions Chris Betz of Microsoft’s Security Response Center deemed “right for Google but not right for customers.” A matter of principle, the search giant would probably reply, and then we’d go back and forth between the equally rational claims of the two arch-rivals.

On one hand, the people have a right to know, but on the other, they’re better off kept in the dark until all is milk and honey again. Or, you know, as close as Windows could ever get to an invulnerable, impenetrable security paradise.

Speaking of your right to know, here’s the bug’s full mind-bending explanation.

Adrian Diaconescu
Former Digital Trends Contributor
Adrian is a mobile aficionado since the days of the Nokia 3310, and a PC enthusiast since Windows 98. Later, he discovered…
Windows 11 users outsmart Microsoft once again with new local account trick
A screenshot of the Windows 11 Microsoft Account setup page

A newly discovered trick allows Windows 11 users to bypass Microsoft’s online account requirement during setup, raising questions around user control and privacy. The workaround, shared by X user @witherornot1337, lets users set up Windows 11 with a local account instead of being forced to log in with a Microsoft account.

This follows previous similar methods, highlighting an ongoing cat-and-mouse game between Microsoft and privacy-conscious users. Microsoft has been increasingly pushing online accounts as a mandatory requirement for Windows 11, particularly in Home and Pro editions. This change has frustrated many users who prefer local accounts for greater privacy and independence from Microsoft’s ecosystem.

Read more
I hope Microsoft adds these 6 things to the next major Windows Update
Windows 11 logo on a laptop.

Windows 11 updates have a bit of a reputation, from slowing Intel's newest desktop processors to breaking games. Despite the occasional hiccup, we still look forward with cautious optimism.

Despite the occasional rough patch, Microsoft continues to evolve the OS, and each update feels like a chance for a new beginning. While Microsoft hasn't confirmed anything yet, the rumor mill is buzzing with what comes next, and I'm starting to feel excited. The talk of new features suggests fixes for long-standing annoyances, productivity boosts, and quality-of-life improvements worth waiting for.
What's coming to Windows in 2025?

Read more
Microsoft could make account-free Windows 11 installs a thing of the past
Windows 11 logo on a laptop.

The offline Windows 11 install looks like it could officially be a thing of the past. 

Microsoft is officially shutting the door on local accounts during Windows 11 setup, confirming that all new installations, Home and Pro alike, will now require a Microsoft account. 

Read more