Close Menu
TechurzTechurz

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Mesa shuts down credit card that rewarded cardholders for paying their mortgages

    December 14, 2025

    India’s Spinny lines up $160M funding to acquire GoMechanic, sources say

    December 14, 2025

    Netflix growing up, data center jet engines, and the circular AI economy

    December 12, 2025
    Facebook X (Twitter) Instagram
    Trending
    • Mesa shuts down credit card that rewarded cardholders for paying their mortgages
    • India’s Spinny lines up $160M funding to acquire GoMechanic, sources say
    • Netflix growing up, data center jet engines, and the circular AI economy
    • What most VCs won’t tell you about raising capital
    • Retro, a photo-sharing app for friends, lets you ‘time-travel’ through your camera roll
    • The market has ‘switched’ and founders have the power now, VCs say
    • Capital is a commodity (but your investor relationships aren’t)
    • Harness hits $5.5B valuation with $240M raise to automate AI’s ‘after-code’ gap
    Facebook X (Twitter) Instagram Pinterest Vimeo
    TechurzTechurz
    • Home
    • AI
    • Apps
    • News
    • Guides
    • Opinion
    • Reviews
    • Security
    • Startups
    TechurzTechurz
    Home»AI»Google patches Chrome vulnerability used for account takeover and MFA bypass
    AI

    Google patches Chrome vulnerability used for account takeover and MFA bypass

    TechurzBy TechurzMay 15, 2025No Comments1 Min Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    Chrome, Google, Smart Phone
    Share
    Facebook Twitter LinkedIn Pinterest Email


    “Unlike other browsers, Chrome resolves the Link header on subresource requests. But what’s the problem? The issue is that the Link header can set a referrer-policy. We can specify unsafe-url and capture the full query parameters,” he wrote.

    Link headers are used by websites to tell a browser about important page resources, for example, images, that it should preload. As part of the HTTP response that happens before the browser encounters any HTML, this accelerates response times. When the browser goes hunting for the resource, usually on a third-party server, it transmits a URL containing information about the requesting site, as allowed by the referrer-policy.

    Unfortunately, in Chrome this URL can also include information with a bearing on security, such as OAuth flows used for authentication.

    Account bypass Chrome Google MFA patches takeover vulnerability
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleThe super-impressive De’Longhi Magnifica Evo drops to a record-low price
    Next Article Bluetooth options for every budget
    Techurz
    • Website

    Related Posts

    Opinion

    How OpenAI and Google see AI changing go-to-market strategies

    November 28, 2025
    Opinion

    Google teams up with Accel to hunt for India’s next AI breakouts

    November 25, 2025
    Opinion

    As consumers ditch Google for ChatGPT, Peec AI raises $21M to help brands adapt

    November 18, 2025
    Add A Comment
    Leave A Reply Cancel Reply

    Top Posts

    College social app Fizz expands into grocery delivery

    September 3, 202524 Views

    A Former Apple Luminary Sets Out to Create the Ultimate GPU Software

    September 25, 202514 Views

    Bosch Series 6 Air Fryer review: a quality single-basket air fryer, perfect for smaller households

    August 3, 20259 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Most Popular

    College social app Fizz expands into grocery delivery

    September 3, 202524 Views

    A Former Apple Luminary Sets Out to Create the Ultimate GPU Software

    September 25, 202514 Views

    Bosch Series 6 Air Fryer review: a quality single-basket air fryer, perfect for smaller households

    August 3, 20259 Views
    Our Picks

    Mesa shuts down credit card that rewarded cardholders for paying their mortgages

    December 14, 2025

    India’s Spinny lines up $160M funding to acquire GoMechanic, sources say

    December 14, 2025

    Netflix growing up, data center jet engines, and the circular AI economy

    December 12, 2025

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms and Conditions
    • Disclaimer
    © 2025 techurz. Designed by Pro.

    Type above and press Enter to search. Press Esc to cancel.