Skip to main content
  1. Home
  2. Computing
  3. News

Google’s Project Zero chastised Trend Micro over security vulnerability

Add as a preferred source on Google

When you pay for security software, you probably hope it’s protecting you — not creating a massive security breach in and of itself. But if you ran Trend Micro’s password manager, enabled by default for all Trend Micro users, any site on the web could have executed any app on your computer just by including a bit of code.

A patch issued today mostly solves the problem. But as Ars Technica reports, that only happened because Google Project Zero team member Tavis Ormandy publicly berated the company.

Recommended Videos

“I don’t even know what to say — how could you enable this thing by default on all your customer machines without getting an audit from a competent security consultant?” wrote Ormandy in a long email exchange the company has since made public.

Ormandy claimed it took him “about 30 seconds” to find the vulnerability, and demonstrated it by quickly building a Web page that could remotely launch the Windows calculator if opened on a computer with the password manager installed and running — regardless if users were using it.

That’s true even if you don’t use the password manager, but it gets worse if you do: A related vulnerability made it possible to read all of a users’ saved usernames and passwords in plain text.

A recent update patches the exploit by only allowing Trend Micro sites to send such commands. If you use Trend Micro, make sure everything is up to date, or you might be extremely exposed to all sorts of problems.

But even if you do update, there still could be problems. As of today, Ormandy is saying this “is not sufficient to prevent attacks,” because something like DNS spoofing could trick your computer into thinking a command is coming from Trend Micro. Ormandy added that “a better solution would be to digital sign requests with a certificate.”

Google Project Zero is a team of security researchers inside Google that find zero-day exploits, problems that would otherwise be exploited by hackers. The team gives software companies 30 days to fix the problem, at which point they make it public. The idea is to make the Internet a safer place by getting these exploits fixed before hackers can use them, though this has prompted controversy: Some companies feel this isn’t enough time. It is more time than a hacker would grant, though.

Justin Pot
Justin's always had a passion for trying out new software, asking questions, and explaining things – tech journalism is the…
Another Googlebook just surfaced online, and this one is from Asus
Asus Googlebook renders reveal a Glow Bar, plenty of ports, and a lightweight chassis
Computer, Electronics, Laptop

Google’s upcoming Googlebook lineup is starting to take shape through leaks. Lenovo has already appeared in several renders, while a recent benchmark leak suggests Dell may bring the XPS name to Google’s new laptop platform. Asus is now the latest manufacturer to surface ahead of launch.

Digital Citizen has published multiple renders of an unannounced Asus Googlebook, showing its lid, keyboard, chassis, and port selection. The laptop could make its official debut at IFA next month. Googlebooks are expected to bring Android apps, ChromeOS technology, deeper phone integration, and Gemini features to a new generation of laptops. Acer, Asus, Dell, HP, and Lenovo are all expected to be part of the first wave.

Read more
I’m done charging things that never leave my desk
Wireless peripherals are better than ever, but I’m starting to value the devices that ask absolutely nothing of me
Computer, Computer Hardware, Computer Keyboard

I have two pairs of wireless earbuds that I rotate during long gaming sessions. When one starts complaining about its battery, I swap in the other pair and put the first one on charge. It’s a mildly ridiculous system, but it works. Apparently, my gaming setup now requires something resembling shift work.

Then my mouse died in the middle of a game.

Read more
Your favorite Edge extension may stop working soon as Microsoft follows Chrome’s lead
Microsoft has announced the transition to Manifest V3, gradually phasing out older browser extensions.
Microsoft Edge on PC and Mobile Featured

Microsoft Edge is finally making the same controversial move that Google Chrome did earlier this year, and it could mean the end of some of the browser's most popular ad blockers. Microsoft has announced that Edge is officially transitioning its extensions ecosystem to Manifest Version 3 (MV3), Google's newer extension platform that promises better security, privacy, and performance. As part of that shift, the browser will gradually stop supporting older Manifest V2 (MV2) extensions over the coming months, meaning legacy extensions such as the original uBlock Origin will eventually stop working in Edge.

What is Manifest V3, and why is Microsoft adopting it?

Read more