Skip to main content
  1. Home
  2. Computing
  3. Web
  4. News

Security researchers find yet another leak in HTTPS, and it won’t be easy to patch

Add as a preferred source on Google

A new attack has the potential to steal everything from email addresses to social security numbers — and security experts have found it running free in the wild. It works by manipulating the way HTTPS responses are delivered across the transmission control protocol (TCP), allowing nefarious actors to decrypt hidden information to extract personal data on targeted users.

The exploit is known as HEIST, which loosely stands for HTTP Encrypted Information can be Stolen Through TCP-Windows (as per Ars) and it’s especially dangerous because it’s capable and simple. When a web user encounters the malicious coding on a web page, it is able to query a number of pages, measuring the sizes of the data that is transmitted when the response comes in.

Recommended Videos

Although that data is protected by HTTPS, using older exploits, nefarious actors may be able to decrypt the data in those packets and thereby discover quite personal data about the individuals affected.

Fortunately the technique was devised by security researchers at the University of Leuven, Belgium, rather than by black-hats. That’s why we’re hearing about it before it’s been utilized for privacy invasions in the wild. The researchers who discovered the exploit, Van Goethem and Mathy Vanhoef, previously disclosed it to both Microsoft and Google, but proved its viability again yesterday by tacking on dangerous code to a New York Times advert.

The pair believe that in the right hands, the security flaw could affect many websites and by extension, many, many users.

Unfortunately, at this time a proper fix doesn’t really exist. End users can disable cookies, which just about makes it impossible for data it sends to be decrypted, but that would also kill the functionality on a lot of sites.

Considering HEIST is merely the means to an end and the exploits that allow the decryption of the HTTPS data have been around for years, this doesn’t seem like a security hole that is going to be patched any time soon. Security researchers aren’t hopeful, either.

Unfortunately this means we’re all left swinging in the wind with how to best protect ourselves. The only positive to it all is that since we need to stumble across malicious code to become vulnerable, sticking to reliable websites which are unlikely to host it is the best way to protect yourself, short from disabling cookies everywhere and walling yourself off from the online world.

Jon Martindale
Jon Martindale covers how to guides, best-of lists, and explainers to help everyone understand the hottest new hardware and…
TSMC might set up a price hike that could come straight for your next phone, laptop, or tablet
Here's what TSMC's rumored 10% chip price increase actually means in dollar terms, and why your next phone or laptop could end up costing more.
TSMC Fab

My wallet flinched the second I saw the words "TSMC" and "price increase" in the same headline, and honestly, yours should too.

Turns out the company behind the silicon powering basically every flagship device out there, including Apple’s A-series and Qualcomm’s Snapdragon processors, is reportedly about to make all of it a little pricier.

Read more
Apple fixes Hide My Email bug that exposed users’ real email addresses
Here's how Apple's Hide My Email flaw leaked real addresses for over a year, and why it only got fixed once the story went public.
apple-merging-sign-in-with-apple-hide-my-email-icloud+

Turns out the "Hide" part of Hide My Email wasn't doing its job quite as advertised, something that I covered early in July. Security researcher Tyler Murphy reported the flaw in June 2025, but despite Apple claiming it was resolved in March 2026, independent tests confirmed it remained exploitable, at least until July 3, 2026.

So how did this bug actually work?

Read more
Gemini Notebook’s new Collections arrive just as Google turns it into a bigger workspace
Google is cleaning up notebook organization as the former NotebookLM expands across Gemini and Search
Gemini Notebook branding on a MacBook

Google has barely finished renaming NotebookLM, and it’s already addressing one of the headaches that comes with building a large research library.

Collections are rolling out to all Gemini Notebook users, giving them a way to group related notebooks while keeping everything visible under My Notebooks. The dashboard gets some structure without asking users to rearrange the library they’ve already built.

Read more